Executive brief
A vulnerability in the Acer Connect M6E 5G portable router allows unauthorized individuals to execute arbitrary commands on the device. This router is used to provide mobile internet connectivity for users and businesses; an exploit could lead to a total takeover of the device, allowing attackers to intercept network traffic or disrupt service. Acer is currently developing a firmware update to address this and several other security issues.
Technical details
An OS command injection vulnerability exists in the FieldX MDM component of the Acer Connect M6E 5G router. The 'adb' messaging topic fails to validate incoming payloads before passing them to the 'Runtime.exec()' function. This allows a remote, unauthenticated attacker to inject and execute arbitrary system commands with the privileges of the application. The vendor has acknowledged the issue and plans to remediate it by replacing shell invocation with rigid allowlisted parameters and introducing command-level authorization.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: disclosed: CVE published by Acer via NVD
- 2026-06-04: advisory: Acer community security advisory published