Junglewise Threat Intelligence

CVE-2026-50208: Acer Connect M6E TLS validation bypass and hard-coded keys

CVE-2026-50208 · Severity: info · CVSS 9.2 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

Acer Connect M6E 5G portable routers contain security flaws that disable standard encryption protections. This allows an attacker positioned on the same network to intercept and decrypt sensitive data transmitted by the device. This could lead to the exposure of private communications, login credentials, or other confidential information.

Technical details

The Acer Connect M6E 5G router firmware contains 'TrustAllCerts' routines that bypass standard TLS certificate validation. This vulnerability is compounded by the use of hard-coded DES symmetric encryption keys. A Man-in-the-Middle (MITM) attacker on the network can exploit these weaknesses to intercept, decrypt, and potentially modify network traffic that should otherwise be protected by TLS. The issue is identified in firmware versions M6E_AI_1.00.000019 and earlier. Acer is reportedly working on firmware updates to address these cryptographic failures.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: advisory: Acer published security advisory and NVD record created.

References

Related threats