Executive brief
The Acer Connect W6x router contains a critical security flaw in how it processes internal messaging. An attacker can send specially crafted messages to the device to take complete control with root-level privileges. This could allow an unauthorized user to intercept internet traffic, access connected devices, or disable the network entirely.
Technical details
A command injection vulnerability (CWE-77) exists in the MQTT broker processing logic of the Acer Connect W6x router. The flaw is caused by a lack of application-level payload sanitization for incoming messaging strings. An unauthenticated attacker can exploit this by sending crafted MQTT messages to the device, leading to arbitrary code execution with root-level permissions. This vulnerability is addressed in firmware version W6x_GBL_2.00.000008 and later.
Affected products
- Acer Connect W6x Router W6x_GBL_2.00.000005 and earlier
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory: Acer published security advisory 19672