Junglewise Threat Intelligence

CVE-2026-50209: Acer Connect M6E MDM hijacking via Broadcast Receiver privilege escalation

CVE-2026-50209 · Severity: info · CVSS 9.3 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

A vulnerability in the Acer Connect M6E 5G portable router allows malicious software installed on the device to hijack its management settings. By exploiting insecure communication channels, an attacker can redirect the device to a rogue management server, effectively taking full administrative control over the router and its data. This could lead to unauthorized monitoring of network traffic or complete loss of device ownership.

Technical details

The vulnerability stems from incorrect permission assignments (CWE-732) within a core Broadcast Receiver component of the Acer Connect M6E router. Specifically, the receiver lacks proper access controls (exported=true without signature-level permissions), allowing unauthorized local applications to trigger administrative operations. An attacker can exploit this by sending a crafted broadcast event to rewrite the default Mobile Device Management (MDM) endpoint address. This shifts administrative ownership to an external attacker-controlled server, enabling full device compromise. Acer is addressing this by restricting the receiver's visibility and enforcing signature-level authorization.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: advisory: Acer published security advisory and NVD entry created.

References

Related threats