Executive brief
The Acer Connect M6E 5G portable router contains hard-coded credentials and resource files that do not expire. This allows unauthorized individuals to potentially access sensitive information or misuse device assets. An exploit could lead to the exposure of private data or unauthorized control over the router's functions.
Technical details
The vulnerability exists within the APK resource files of the Acer Connect M6E 5G router firmware. Fixed resource files contain non-expiring shared 'scepters' (credentials/tokens) that are hard-coded into the application. An attacker can extract these static credentials to gain unauthorized access to sensitive information or perform unauthorized actions on the device. The issue is categorized as CWE-200 (Exposure of Sensitive Information). Acer has recommended transitioning to dynamic, per-device issuance of credentials with automated rotation to remediate the flaw.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: advisory: Initial disclosure by Acer and NVD publication