Junglewise Threat Intelligence

CVE-2026-49197: Acer Connect W6x Router authentication bypass in app endpoints

CVE-2026-49197 · Severity: info · CVSS 10 · Published 2026-05-29

Technologies: Acer Connect W6x Router. Vendors: Acer.

Executive brief

Acer Connect W6x routers contain a critical security flaw in how they handle login requests from the mobile management app. An attacker can bypass the router's security checks by sending a specially formatted request that causes the authentication system to fail and grant access. This could allow an unauthorized person to take full control of the router, potentially compromising the home network and internet traffic.

Technical details

A critical authentication bypass vulnerability exists in the web endpoints of the Acer Connect W6x router intended for use with the Acer Connect mobile application. The root cause is improper validation of the HTTP Authorization header; specifically, the system fails to block or reject requests when the Base64 decoding of the credentials fails, leading to an 'open' state or bypassed check. A remote, unauthenticated attacker can exploit this by sending malformed headers to gain full administrative access to the device. This issue is tracked as CWE-287 and has been addressed in firmware version W6x_GBL_2.00.000008.

Affected products

  • Acer Connect W6x Router W6x_GBL_2.00.000005 and earlier

Timeline

  • 2026-05-29: advisory: Acer published the security advisory and firmware update.
  • 2026-05-29: disclosed: CVE-2026-49197 was published to the NVD.

References

Related threats