Executive brief
The Acer Connect M6E 5G portable router contains a vulnerability in a system utility that allows unauthenticated users to execute commands with full administrative (root) privileges. This could allow an attacker on the same network to take complete control of the device, potentially leading to data interception or persistent unauthorized access. Acer is currently developing firmware updates to address this issue.
Technical details
The vulnerability exists within the 'ai_cmd' utility of the Acer Connect M6E 5G router. The utility runs with full root privileges and improperly handles communication by piping socket inputs directly into the popen() function without validation or authentication. This allows an unauthenticated attacker within adjacent network range to execute arbitrary shell commands as root. Acer has indicated that a resolution will involve replacing popen() with rigid allowlisted command parameterization, dropping root privileges, and implementing SELinux barriers.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: disclosed: CVE published and advisory released by Acer