Executive brief
Acer Connect M6E 5G portable routers contain security flaws that disable standard encryption protections. This allows an attacker positioned on the same network to intercept and decrypt sensitive data transmitted by the device. This could lead to the exposure of private communications, login credentials, or other confidential information.
Technical details
The Acer Connect M6E 5G router firmware contains 'TrustAllCerts' routines that bypass standard TLS certificate validation. This vulnerability is compounded by the use of hard-coded DES symmetric encryption keys. A Man-in-the-Middle (MITM) attacker on the network can exploit these weaknesses to intercept, decrypt, and potentially modify network traffic that should otherwise be protected by TLS. The issue is identified in firmware versions M6E_AI_1.00.000019 and earlier. Acer is reportedly working on firmware updates to address these cryptographic failures.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: advisory: Acer published security advisory and NVD record created.