Executive brief
A vulnerability in the Acer Connect M6E 5G portable router allows unauthorized local software to perform administrative tasks. This occurs because a core communication component lacks proper access controls, potentially allowing a malicious app on a connected device to change system settings. An exploit could lead to unauthorized configuration changes or a compromise of the router's management functions.
Technical details
The vulnerability is a privilege escalation (CWE-269) within the Android-based firmware of the Acer Connect M6E 5G router. A core Broadcast Receiver is exported with public access permissions but lacks proper validation of the calling component. A local attacker or a malicious application on the device can send intents to this receiver to trigger administrative operations without authorization. Acer recommends updating firmware to versions that set 'exported=false' or enforce signature-level permissions for this component.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: disclosed
- 2026-06-04: advisory