Executive brief
The Acer Connect M6E 5G portable router contains a security flaw where the system does not properly verify certain internal commands. This allows a malicious application installed on the device to read sensitive cellular configuration files or disable the device's internet connectivity entirely. This could lead to a loss of service or the exposure of private mobile network data.
Technical details
The vulnerability exists within the system Binder boundary of the Acer Connect M6E 5G router. The component fails to verify pass-through AT commands, which are typically used for low-level communication with the cellular modem. A local attacker with low privileges can exploit this by sending unverified commands to the baseband processor. Successful exploitation allows the attacker to read sensitive baseband files, modify cellular configurations, or perform a denial-of-service by disabling cellular connectivity. Acer has identified this as part of a broader set of vulnerabilities and is working on firmware updates to implement stricter command validation.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: advisory: Initial disclosure by Acer and NVD publication