Executive brief
The Acer Connect M6E 5G portable router contains a security flaw where sensitive backend API keys are hard-coded into its web server component. These keys can be exposed to unauthorized users through detailed error messages displayed by the device. An attacker who obtains these keys could potentially gain unauthorized access to backend services, compromising the security and privacy of the device and its owner.
Technical details
The M3WebServer component in Acer Connect M6E firmware contains hard-coded backend API keys. Due to improper error handling (CWE-287), these keys are leaked in verbose error pages generated by the web server. A remote, unauthenticated attacker can trigger these error pages to intercept the keys. This allows for unauthorized authentication to backend services. Acer plans to remediate this by transitioning to dynamic device-level certificate validation and obscuring diagnostic error outputs in future firmware updates.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: advisory: NVD and Acer published the vulnerability details.