acer / connect_m6e_5g
26 known vulnerabilities in acer connect_m6e_5g.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-49190 | Medium | 0.4% | 8.8 | The system fails to evaluate instructional permissions over multiple internal op… | |
| CVE-2026-49185 | Medium | 0.4% | 9.8 | The FieldX MDM adb messaging topic passes unverified payloads directly into Runt… | |
| CVE-2026-49186 | Medium | 0.3% | 9.8 | The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). … | |
| CVE-2026-49188 | Medium | 0.3% | 9.8 | The ai_cmd utility executes with full root permissions. It pipes socket inputs d… | |
| CVE-2026-49191 | Medium | 0.3% | 9.8 | The production build of the M3WebServer hard-codes its backend API keys, which c… | |
| CVE-2026-50211 | Medium | 0.3% | 9.8 | Leftover engineering diagnostics and factory-level diagnostic software remain ex… | |
| CVE-2026-49202 | Medium | 0.3% | 8.6 | Internal multimedia session archives are accessible without authentication, exac… | |
| CVE-2026-49187 | Medium | 0.2% | 7.5 | The hard-coded APK resource files never expire, and the shared scepter leads to … | |
| CVE-2026-49193 | Medium | 0.2% | 7.5 | Overly permissive configuration settings on cloud storage containers expose acti… | |
| CVE-2026-50210 | Medium | 0.2% | 7.5 | The device encrypts data using AES-CBC with static zero-filled Initialization Ve… | |
| CVE-2026-50225 | Medium | 0.2% | 9.1 | The registration path /v1/account/register provides no bot mitigation mechanisms… | |
| CVE-2026-50205 | Medium | 0.2% | 8.2 | System log files output unencrypted SMTP server authentication passwords alongsi… | |
| CVE-2026-49194 | Medium | 0.2% | 8.8 | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standa… | |
| CVE-2026-50213 | Medium | 0.2% | 7.5 | The account validation endpoint /v1/User/validate returns comprehensive user pro… | |
| CVE-2026-49203 | Medium | 0.2% | 8.3 | Crucial management API endpoints for cellular eSIM allocation do not validate ca… | |
| CVE-2026-50214 | Medium | 0.2% | 9.8 | The /v1/Plan service relies entirely on a shared global API token for full admin… | |
| CVE-2026-50208 | Medium | 0.1% | 9.4 | High-risk TrustAllCerts routines disable standard TLS certificate validation. Co… | |
| CVE-2026-50207 | Medium | 0.1% | 7.8 | The system Binder boundary accepts unverified pass-through AT commands, giving l… | |
| CVE-2026-49189 | Medium | 0.1% | 7.8 | Unchecked public access permissions on a core Broadcast Receiver allow unauthori… | |
| CVE-2026-50209 | Medium | 0.1% | 7.8 | Broadcast events allow malicious software to rewrite the device's default Mobile… | |
| CVE-2026-50206 | Low | 0.7% | 6.8 | Incoming VPN network profile settings fail to process special characters safely,… | |
| CVE-2026-50224 | Low | 0.2% | 4.9 | The web administration panel binds broadly to the public IPv6 address space on p… | |
| CVE-2026-50226 | Low | 0.2% | 5.3 | Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forg… | |
| CVE-2026-50212 | Low | 0.2% | 6.5 | Weak validation logic within device dissociation API routines allows a remote en… | |
| CVE-2026-49204 | Low | 0.2% | 6.5 | Leftover debug modules contain fixed credentials for internal AWS Cognito test s… | |
| CVE-2026-49192 | Low | 0.1% | 5.4 | The summary service endpoint suffers from an IDOR vulnerability where it fails t… |