Executive brief
The Acer Connect M6E 5G portable router contains a security flaw where it fails to properly check permissions for certain internal commands. This allows an attacker to bypass security restrictions to install unauthorized applications or execute arbitrary commands on the device. Such an exploit could lead to a complete takeover of the router, potentially compromising the user's internet traffic and local network security.
Technical details
The vulnerability stems from missing per-instruction authorization checks within the router's firmware. Specifically, the system fails to evaluate permissions for multiple internal operation codes (opcodes). An attacker with network access and low-level privileges can exploit this lack of Role-Based or Attribute-Based Access Control (RBAC/ABAC) to execute sensitive operations, install unauthorized software, or run arbitrary commands. Acer has indicated that a resolution involves introducing RBAC/ABAC at every opcode layer and implementing audit logging for sensitive operations.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: disclosed: CVE published and Acer advisory released