Junglewise Threat Intelligence

CVE-2026-50211: Acer Connect M6E exposed engineering diagnostics in firmware

CVE-2026-50211 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains leftover engineering and factory diagnostic software that was not removed before the product was sold. This allows malicious applications or unauthorized users to modify internal system settings (NVRAM), potentially leading to device instability or unauthorized configuration changes. This could result in a loss of service or allow an attacker to gain persistent control over the router's hardware settings.

Technical details

This vulnerability stems from the failure to remove debugging and factory diagnostic tools from production firmware builds. These exposed interfaces allow malicious local applications or potentially remote attackers to gain write privileges to internal NVRAM (Non-Volatile Random-Access Memory) registers. The root cause is categorized as a format string vulnerability (CWE-134) within the diagnostic routines. Exploitation can lead to unauthorized modification of critical system parameters, privilege escalation, or persistent device compromise. Acer is addressing this by removing testing/backdoor opcodes and diagnostic software from operational firmware.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier

Timeline

  • 2026-06-04: disclosed: CVE published by Acer and NVD
  • 2026-06-04: advisory: Acer security advisory published

References

Related threats