Executive brief
The Acer Connect M6E 5G portable router contains a security flaw where internal meeting recordings and multimedia archives are accessible to anyone on the network without a password. Additionally, weak web security settings (CORS) could allow a malicious website to steal these recordings if a user visits the site while connected to the router. This could result in the unauthorized exposure of private conversations and sensitive session data.
Technical details
The Acer Connect M6E 5G router suffers from improper authentication (CWE-287) in its multimedia session archive endpoints. Internal meeting recordings are stored in a manner that does not require a valid session or credentials for access. This is further compounded by overly permissive Cross-Origin Resource Sharing (CORS) policies, which allow an attacker to perform cross-site data theft if a victim's browser interacts with a malicious origin while connected to the router's local network. Attackers can remotely access and download these archives without any prior authorization. Acer is developing a firmware update to implement signed download links and restricted CORS headers.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: disclosed: CVE published and Acer advisory released