Executive brief
A vulnerability in the Acer Connect M6E 5G portable router allows unauthorized users to manage network access plans. By exploiting a shared administrative token, an attacker could create network plans at no cost or modify existing administrative settings. This could lead to financial loss for the service provider and unauthorized control over the device's networking functions.
Technical details
The /v1/Plan service in the Acer Connect M6E 5G router firmware relies on a shared global API token for full administrative management. This design flaw allows any user with knowledge of the token to perform administrative actions, such as creating arbitrary zero-cost network access plans. The vulnerability is categorized as insufficient verification of data authenticity (CWE-345). It is accessible over the network without requiring unique user authentication. Acer has indicated that remediation involves transitioning to dynamic, per-device validation and improving authorization checks.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: advisory: Acer published the security advisory and NVD published the CVE record.