Executive brief
A vulnerability in the Acer Connect M6E 5G portable router allows unauthorized users to bypass the standard login screen. By using a specific debugging command, an attacker can gain direct access to the device's internal command-line interface. This could lead to a complete takeover of the router, allowing attackers to monitor network traffic, change settings, or disable the device.
Technical details
The vulnerability exists within a debugging routine identified as SCREEN_CLICK(5053). This routine fails to enforce authentication boundaries, allowing a connection to bypass the standard device login prompt and drop directly into an interactive shell interface. According to the vendor's CVSS 4.0 assessment, the flaw is reachable over the network with low privileges. Exploitation grants the attacker high-impact access to the underlying operating system (shell access), compromising confidentiality, integrity, and availability. Acer has recommended removing these testing/backdoor opcodes from operational firmware as a remediation strategy.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: advisory: Initial disclosure by Acer and NVD publication