Executive brief
Acer Connect M6E 5G portable routers contain a security flaw in how they manage device connections. An attacker on the same network can exploit this to remotely disconnect other users' devices from the router. This results in a denial of service, preventing legitimate users from accessing the internet or network resources.
Technical details
A vulnerability exists in the device dissociation API routines of the Acer Connect M6E 5G router due to weak validation logic. An attacker with adjacent network access can exploit this flaw to forcefully unbind or disconnect endpoints belonging to other users without proper authorization. This is categorized as a denial-of-service (DoS) attack (CWE-400). The issue affects firmware versions M6E_AI_1.00.000019 and earlier. Acer has indicated that a firmware update is being developed to implement stronger validation and binding of tokens to physical device IDs.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: disclosed
- 2026-06-04: advisory