Junglewise Threat Intelligence

CVE-2026-49191: Acer Connect M6E hard-coded API keys in M3WebServer

CVE-2026-49191 · Severity: info · CVSS 9.3 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains a security flaw where sensitive backend API keys are hard-coded into its web server component. These keys can be exposed to unauthorized users through detailed error messages displayed by the device. An attacker who obtains these keys could potentially gain unauthorized access to backend services, compromising the security and privacy of the device and its owner.

Technical details

The M3WebServer component in Acer Connect M6E firmware contains hard-coded backend API keys. Due to improper error handling (CWE-287), these keys are leaked in verbose error pages generated by the web server. A remote, unauthenticated attacker can trigger these error pages to intercept the keys. This allows for unauthorized authentication to backend services. Acer plans to remediate this by transitioning to dynamic device-level certificate validation and obscuring diagnostic error outputs in future firmware updates.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier

Timeline

  • 2026-06-04: advisory: NVD and Acer published the vulnerability details.

References

Related threats