Junglewise Threat Intelligence

CVE-2026-49192: Acer Connect M6E IDOR in summary service endpoint

CVE-2026-49192 · Severity: info · CVSS 5.3 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains a security flaw in its summary service. This vulnerability allows an authenticated user to access information about other devices they do not own by guessing or providing different hardware serial numbers. This could lead to the unauthorized collection of device data and potential privacy risks for users.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the summary service endpoint of the Acer Connect M6E 5G router. The application fails to perform an authorization check to ensure that the requesting user is the legitimate owner of the hardware serial number provided in the request. An attacker with valid credentials can exploit this by iterating through serial numbers to scrape device data from the backend service. Acer has indicated that a firmware update is planned to mandate rigorous user-to-device association validation.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: disclosed: Initial advisory publication by Acer and NVD record creation.

References

Related threats