Junglewise Threat Intelligence

CVE-2026-49187: Acer Connect M6E hard-coded credentials in APK resources

CVE-2026-49187 · Severity: info · CVSS 8.7 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains hard-coded credentials and resource files that do not expire. This allows unauthorized individuals to potentially access sensitive information or misuse device assets. An exploit could lead to the exposure of private data or unauthorized control over the router's functions.

Technical details

The vulnerability exists within the APK resource files of the Acer Connect M6E 5G router firmware. Fixed resource files contain non-expiring shared 'scepters' (credentials/tokens) that are hard-coded into the application. An attacker can extract these static credentials to gain unauthorized access to sensitive information or perform unauthorized actions on the device. The issue is categorized as CWE-200 (Exposure of Sensitive Information). Acer has recommended transitioning to dynamic, per-device issuance of credentials with automated rotation to remediate the flaw.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier

Timeline

  • 2026-06-04: advisory: Initial disclosure by Acer and NVD publication

References

Related threats