Executive brief
The Acer Connect M6E 5G portable router contains a security flaw in its internal messaging system (MQTT). This vulnerability allows an attacker to bypass intended restrictions to discover hidden network devices or send unauthorized control commands to the router. This could lead to a loss of privacy or unauthorized changes to the device's configuration and operation.
Technical details
The local MQTT broker on affected Acer Connect M6E devices does not enforce topic-level Access Control Lists (ACLs). An attacker with network access to the broker can utilize MQTT wildcard characters ('#' or '+') to subscribe to all topics, enabling the enumeration of hidden network devices and the interception of sensitive telemetry. Furthermore, the lack of enforcement allows for the publication of rogue control commands to topics that should be restricted. While the CVSS vector indicates high privileges (PR:H) may be required, the lack of ACL enforcement effectively bypasses intended authorization boundaries for any connected client. Acer is working on a firmware update to enforce ACLs and ban global wildcards for non-administrative roles.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: advisory: Acer published security advisory and NVD entry created.