Junglewise Threat Intelligence

CVE-2026-49195: Acer Connect W6x unauthenticated debug service in mtk_dut

CVE-2026-49195 · Severity: info · CVSS 8.7 · Published 2026-05-29

Technologies: Acer Connect W6x Router. Vendors: Acer.

Executive brief

Acer Connect W6x routers contain a security flaw where a debugging service is left open without a password. An attacker on the same local network (such as a guest or someone connected to the Wi-Fi) can access this service to execute commands on the router. This could lead to a full takeover of the device, allowing the attacker to monitor network traffic or disrupt internet connectivity.

Technical details

The vulnerability is a missing authentication flaw (CWE-306) in the /sbin/mtk_dut binary, which is exposed on TCP port 9000. This service is intended for debugging but lacks any access control, allowing an unauthenticated attacker on the local area network (LAN) or adjacent network to interact with the interface. By sending arbitrary UCC commands to this port, an attacker can achieve remote code execution with the privileges of the service. The issue is resolved in firmware version W6x_GBL_2.00.000008 and later.

Affected products

  • Acer Connect W6x Router W6x_GBL_2.00.000005 and earlier

Timeline

  • 2026-05-29: advisory: Acer published the security advisory and NVD entry.
  • 2026-05-29: patched: Firmware version W6x_GBL_2.00.000008 released to address the issue.

References

Related threats