Junglewise Threat Intelligence

CVE-2026-49186: Acer Connect M6E missing MQTT topic access control

CVE-2026-49186 · Severity: info · CVSS 8.6 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains a security flaw in its internal messaging system (MQTT). This vulnerability allows an attacker to bypass intended restrictions to discover hidden network devices or send unauthorized control commands to the router. This could lead to a loss of privacy or unauthorized changes to the device's configuration and operation.

Technical details

The local MQTT broker on affected Acer Connect M6E devices does not enforce topic-level Access Control Lists (ACLs). An attacker with network access to the broker can utilize MQTT wildcard characters ('#' or '+') to subscribe to all topics, enabling the enumeration of hidden network devices and the interception of sensitive telemetry. Furthermore, the lack of enforcement allows for the publication of rogue control commands to topics that should be restricted. While the CVSS vector indicates high privileges (PR:H) may be required, the lack of ACL enforcement effectively bypasses intended authorization boundaries for any connected client. Acer is working on a firmware update to enforce ACLs and ban global wildcards for non-administrative roles.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: advisory: Acer published security advisory and NVD entry created.

References

Related threats