Executive brief
Acer Connect W6x routers, which provide wireless internet connectivity for homes and offices, contain a security flaw in their device management interface. An attacker with administrative access can exploit the Wi-Fi device blocking feature to run unauthorized system commands. This could allow a malicious actor to take full control of the router, potentially leading to network surveillance or service disruption.
Technical details
A command injection vulnerability (CWE-77) exists in the Web Admin Panel of Acer Connect W6x routers. The vulnerability is located within the Wi-Fi device blocking feature, where the application fails to properly sanitize input in MAC address fields. An authenticated attacker with high privileges (administrator) can inject special characters to execute arbitrary shell commands on the underlying operating system. The attack is reachable over the network via the web interface. Acer has addressed this in firmware version W6x_GBL_2.00.000008 by refining input validation logic.
Affected products
- Acer Connect W6x Router W6x_GBL_2.00.000005 and earlier
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
- 2026-05-29: patched: Fixed in firmware version W6x_GBL_2.00.000008