Junglewise Threat Intelligence

CVE-2026-49189: Acer Connect M6E Broadcast Receiver privilege escalation

CVE-2026-49189 · Severity: info · CVSS 8.5 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

A vulnerability in the Acer Connect M6E 5G portable router allows unauthorized local software to perform administrative tasks. This occurs because a core communication component lacks proper access controls, potentially allowing a malicious app on a connected device to change system settings. An exploit could lead to unauthorized configuration changes or a compromise of the router's management functions.

Technical details

The vulnerability is a privilege escalation (CWE-269) within the Android-based firmware of the Acer Connect M6E 5G router. A core Broadcast Receiver is exported with public access permissions but lacks proper validation of the calling component. A local attacker or a malicious application on the device can send intents to this receiver to trigger administrative operations without authorization. Acer recommends updating firmware to versions that set 'exported=false' or enforce signature-level permissions for this component.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: disclosed
  • 2026-06-04: advisory

References

Related threats