Junglewise Threat Intelligence

CVE-2026-49204: Acer Connect M6E 5G hard-coded AWS credentials in debug modules

CVE-2026-49204 · Severity: info · CVSS 6.9 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains leftover development modules that include fixed login credentials for internal testing environments. An attacker could use these credentials to access cloud-based test sandboxes, potentially leading to the misuse of company assets or exposure of internal testing data. This issue stems from debugging tools that were not properly removed before the product was released to the public.

Technical details

The firmware for the Acer Connect M6E 5G router (version M6E_AI_1.00.000019 and earlier) contains hard-coded credentials (CWE-798) within leftover debug modules. These credentials provide access to internal AWS Cognito test sandboxes used during development. An unauthenticated attacker with network access to the firmware or device components can extract these fixed credentials to gain unauthorized access to the associated cloud testing environments. Acer has advised that a firmware update is being developed to expunge these testing/backdoor opcodes and transition to dynamic credential management.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: disclosed: CVE published and NVD record created
  • 2026-06-04: advisory: Acer community advisory published

References

Related threats