Junglewise Threat Intelligence

CVE-2026-49199: Acer Connect W6x command injection in MQTT broker

CVE-2026-49199 · Severity: info · CVSS 10 · Published 2026-05-29

Technologies: Acer Connect W6x Router. Vendors: Acer.

Executive brief

The Acer Connect W6x router contains a critical security flaw in how it processes internal messaging. An attacker can send specially crafted messages to the device to take complete control with root-level privileges. This could allow an unauthorized user to intercept internet traffic, access connected devices, or disable the network entirely.

Technical details

A command injection vulnerability (CWE-77) exists in the MQTT broker processing logic of the Acer Connect W6x router. The flaw is caused by a lack of application-level payload sanitization for incoming messaging strings. An unauthenticated attacker can exploit this by sending crafted MQTT messages to the device, leading to arbitrary code execution with root-level permissions. This vulnerability is addressed in firmware version W6x_GBL_2.00.000008 and later.

Affected products

  • Acer Connect W6x Router W6x_GBL_2.00.000005 and earlier

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory: Acer published security advisory 19672

References

Related threats