Junglewise Threat Intelligence

CVE-2026-49193: Acer Connect M6E information disclosure in AWS S3 telemetry buckets

CVE-2026-49193 · Severity: info · CVSS 8.7 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

Acer Connect M6E 5G portable routers are affected by a cloud configuration error that exposes device telemetry data to the public internet. This means that sensitive diagnostic and usage information, which should be private, can be accessed by anyone without a password. An attacker could use this information to monitor device activity or gather data for further targeted attacks.

Technical details

The vulnerability is a case of sensitive information disclosure (CWE-200) resulting from misconfigured AWS S3 buckets. Specifically, the cloud storage containers used to store active telemetry data from Acer Connect M6E 5G routers were set with overly permissive access controls, lacking the 'Block Public Access' setting. This allows unauthenticated remote actors to read telemetry logs directly over the network. Acer has recommended remediating this by enabling S3 Block Public Access and implementing restrictive bucket policies based on the principle of least privilege.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: disclosed: CVE published and Acer advisory released

References

Related threats