Executive brief
Acer Connect M6E 5G portable routers are affected by a security flaw where sensitive information is recorded in plain text within system logs. This includes email server passwords and corporate employee identification data. An attacker who gains access to these logs could use the stolen credentials to compromise email accounts or misuse employee identity information, potentially leading to further unauthorized access to corporate resources.
Technical details
The Acer Connect M6E 5G router firmware (vM6E_AI_1.00.000019 and earlier) suffers from CWE-532, where sensitive information is inserted into system log files. Specifically, the logs contain unencrypted SMTP authentication passwords and corporate employee ID data. While the NVD entry lists a network attack vector, this typically implies the logs are accessible via a network-reachable management interface or telemetry service. An attacker obtaining these logs can perform credential theft and identity impersonation. Acer is reportedly working on a firmware update to remediate these logging practices.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: disclosed: CVE-2026-50205 published to NVD
- 2026-06-04: advisory: Acer published security advisory 19707