Executive brief
Acer Connect M6E 5G portable routers are affected by a cloud configuration error that exposes device telemetry data to the public internet. This means that sensitive diagnostic and usage information, which should be private, can be accessed by anyone without a password. An attacker could use this information to monitor device activity or gather data for further targeted attacks.
Technical details
The vulnerability is a case of sensitive information disclosure (CWE-200) resulting from misconfigured AWS S3 buckets. Specifically, the cloud storage containers used to store active telemetry data from Acer Connect M6E 5G routers were set with overly permissive access controls, lacking the 'Block Public Access' setting. This allows unauthenticated remote actors to read telemetry logs directly over the network. Acer has recommended remediating this by enabling S3 Block Public Access and implementing restrictive bucket policies based on the principle of least privilege.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: disclosed: CVE published and Acer advisory released