Junglewise Threat Intelligence

CVE-2026-50213: Acer Connect M6E IDOR in account validation endpoint

CVE-2026-50213 · Severity: info · CVSS 8.7 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

An information disclosure vulnerability exists in the Acer Connect M6E 5G portable router. The device's account validation service allows anyone to download detailed user profile data by guessing or iterating through predictable identification strings. This could lead to the large-scale harvesting of customer information and private account details.

Technical details

The Acer Connect M6E 5G router suffers from an Insecure Direct Object Reference (IDOR) and information disclosure vulnerability in its account validation endpoint (/v1/User/validate). The API returns comprehensive user profile data sheets without sufficient authorization checks. An unauthenticated remote attacker can exploit this by iterating through predictable identification strings (such as sequential IDs or hardware serial numbers) to crawl and harvest sensitive user data. Acer has indicated that a firmware update is required to mandate rigorous user-to-device association validation.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: disclosed: Initial advisory publication
  • 2026-06-04: advisory: NVD record published

References

Related threats