Junglewise Threat Intelligence

CVE-2026-49194: Acer Connect M6E authentication bypass via SCREEN_CLICK debugging routine

CVE-2026-49194 · Severity: info · CVSS 9.4 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

A vulnerability in the Acer Connect M6E 5G portable router allows unauthorized users to bypass the standard login screen. By using a specific debugging command, an attacker can gain direct access to the device's internal command-line interface. This could lead to a complete takeover of the router, allowing attackers to monitor network traffic, change settings, or disable the device.

Technical details

The vulnerability exists within a debugging routine identified as SCREEN_CLICK(5053). This routine fails to enforce authentication boundaries, allowing a connection to bypass the standard device login prompt and drop directly into an interactive shell interface. According to the vendor's CVSS 4.0 assessment, the flaw is reachable over the network with low privileges. Exploitation grants the attacker high-impact access to the underlying operating system (shell access), compromising confidentiality, integrity, and availability. Acer has recommended removing these testing/backdoor opcodes from operational firmware as a remediation strategy.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: advisory: Initial disclosure by Acer and NVD publication

References

Related threats