Executive brief
The Acer Connect M6E 5G portable router uses a weak encryption method that relies on static, predictable values. This flaw could allow an attacker to replay intercepted data or potentially decrypt sensitive information transmitted by the device. This compromises the privacy of the data being sent through the router and could lead to unauthorized access to communications.
Technical details
The device implements AES encryption in Cipher Block Chaining (CBC) mode using a static, zero-filled Initialization Vector (IV). In CBC mode, the IV should be unique and unpredictable for every encryption operation to ensure that identical plaintexts result in different ciphertexts. By using a fixed IV, the implementation becomes vulnerable to replay attacks and known-plaintext attacks, allowing an attacker to potentially decrypt traffic or manipulate data streams. The vulnerability is identified as CVE-2026-50210 and affects firmware versions up to M6E_AI_1.00.000019.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: disclosed
- 2026-06-04: advisory