Junglewise Threat Intelligence

CVE-2026-50224: Acer Connect M6E 5G Router Information Exposure in Web Admin Panel

CVE-2026-50224 · Severity: info · CVSS 6.9 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains a configuration flaw where its web administration panel is accessible over the public internet via IPv6. This allows remote individuals to reach internal management interfaces that are normally intended to be private. An attacker could potentially access sensitive device information or internal system functions, compromising the privacy and security of the router.

Technical details

The vulnerability stems from an insecure default configuration where the web administration panel binds to the global IPv6 address [::]:8080. Because there are no default firewall rules to limit this binding, internal API endpoints become reachable over the Wide Area Network (WAN). An attacker with network reachability to the device's IPv6 address can interact with these internal interfaces. While the CVSS metric suggests high privileges (PR:H) may be required for certain impacts, the exposure itself allows for unauthorized information disclosure (CWE-200). Acer is addressing this by implementing default firewall limits and restricting service bindings.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier

Timeline

  • 2026-06-04: disclosed: Initial advisory publication

References

Related threats