Vulnerabilities (CVE)

Filtered by vendor Acer Subscribe
Total 55 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-9490 1 Acer 1 Care Center 2026-07-23 N/A 5.5 MEDIUM
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe, causing the service to crash with exit code 1067 (ERROR_PROCESS_ABORTED). To mitigate this potential local service disruption, Acer requires users to update the software to the latest version.
CVE-2026-50225 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.1 CRITICAL
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
CVE-2026-50206 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 6.8 MEDIUM
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
CVE-2026-49191 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.8 CRITICAL
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
CVE-2026-49203 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 8.3 HIGH
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
CVE-2026-50213 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.5 HIGH
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
CVE-2026-49190 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 8.8 HIGH
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
CVE-2026-49187 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.5 HIGH
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
CVE-2026-49193 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.5 HIGH
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
CVE-2026-50209 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.8 HIGH
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
CVE-2026-50208 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.4 CRITICAL
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
CVE-2026-50226 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 5.3 MEDIUM
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.
CVE-2026-49202 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 8.6 HIGH
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
CVE-2026-50205 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 8.2 HIGH
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
CVE-2026-50211 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.8 CRITICAL
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
CVE-2026-49194 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 8.8 HIGH
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
CVE-2026-50210 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.5 HIGH
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
CVE-2026-50214 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.8 CRITICAL
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
CVE-2026-49185 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.8 CRITICAL
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
CVE-2026-50212 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 6.5 MEDIUM
Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.