Junglewise Threat Intelligence

CVE-2026-49190: Acer Connect M6E missing authorization for internal opcodes

CVE-2026-49190 · Severity: info · CVSS 9.4 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains a security flaw where it fails to properly check permissions for certain internal commands. This allows an attacker to bypass security restrictions to install unauthorized applications or execute arbitrary commands on the device. Such an exploit could lead to a complete takeover of the router, potentially compromising the user's internet traffic and local network security.

Technical details

The vulnerability stems from missing per-instruction authorization checks within the router's firmware. Specifically, the system fails to evaluate permissions for multiple internal operation codes (opcodes). An attacker with network access and low-level privileges can exploit this lack of Role-Based or Attribute-Based Access Control (RBAC/ABAC) to execute sensitive operations, install unauthorized software, or run arbitrary commands. Acer has indicated that a resolution involves introducing RBAC/ABAC at every opcode layer and implementing audit logging for sensitive operations.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: disclosed: CVE published and Acer advisory released

References

Related threats