Executive brief
The Acer Connect M6E 5G portable router contains a security flaw in how it manages cellular eSIM profiles. Because the management interface does not verify who is making a request, an unauthorized person on the same network could remotely rewrite or delete the device's cellular connection profiles. This could lead to a complete loss of internet connectivity or the redirection of cellular service to an unauthorized account.
Technical details
The vulnerability is classified as Improper Authentication (CWE-287) within the eSIM management API of the Acer Connect M6E 5G router. Specifically, crucial endpoints responsible for cellular eSIM allocation do not perform authorization checks on callers. An unauthenticated attacker with adjacent network access can exploit this to modify or delete remote eSIM profiles. Acer has acknowledged the issue and is working on a firmware update to implement token-based validation and device ID binding for these endpoints.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: advisory: Initial disclosure by Acer and NVD publication