Junglewise Threat Intelligence

CVE-2026-49203: Acer Connect M6E improper authentication in eSIM management API

CVE-2026-49203 · Severity: info · CVSS 7.2 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains a security flaw in how it manages cellular eSIM profiles. Because the management interface does not verify who is making a request, an unauthorized person on the same network could remotely rewrite or delete the device's cellular connection profiles. This could lead to a complete loss of internet connectivity or the redirection of cellular service to an unauthorized account.

Technical details

The vulnerability is classified as Improper Authentication (CWE-287) within the eSIM management API of the Acer Connect M6E 5G router. Specifically, crucial endpoints responsible for cellular eSIM allocation do not perform authorization checks on callers. An unauthenticated attacker with adjacent network access can exploit this to modify or delete remote eSIM profiles. Acer has acknowledged the issue and is working on a firmware update to implement token-based validation and device ID binding for these endpoints.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier

Timeline

  • 2026-06-04: advisory: Initial disclosure by Acer and NVD publication

References

Related threats