Executive brief
Acer Connect M6E 5G portable routers are affected by a security flaw in how they handle VPN configuration files. An attacker with administrative access can use specially crafted settings to run unauthorized commands on the device. This could lead to a complete takeover of the router, potentially allowing the attacker to intercept network traffic or disrupt internet connectivity.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Acer Connect M6E 5G Portable WiFi Router due to improper neutralization of special elements in incoming VPN network profile settings. The vulnerability allows an attacker with high privileges (administrative access) to execute arbitrary commands on the underlying operating system by supplying a malicious configuration file containing unsanitized special characters. The attack vector is classified as 'Adjacent' (AV:A), suggesting it may be exploitable via the local network or wireless interface. Acer has indicated that firmware updates are being developed to address this and several other vulnerabilities identified in the M6E platform.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: disclosed: CVE published and NVD entry created
- 2026-06-04: advisory: Acer community advisory published