Junglewise Threat Intelligence

CVE-2026-50225: Acer Connect M6E missing bot mitigation in registration endpoint

CVE-2026-50225 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Acer Connect M6E 5G Portable WiFi Router. Vendors: Acer.

Executive brief

The Acer Connect M6E 5G portable router contains a vulnerability in its account registration process that lacks protection against automated bots. This allows malicious actors to use automated scripts to create a massive number of fake accounts, potentially overwhelming the device's database and causing service disruptions. This could lead to a denial-of-service condition where legitimate users are unable to manage their devices or access services.

Technical details

The registration path /v1/account/register in Acer Connect M6E firmware (up to version M6E_AI_1.00.000019) does not implement rate limiting, CAPTCHAs, or other bot mitigation mechanisms. This is classified as a missing authentication for a critical function (CWE-306). A remote, unauthenticated attacker can exploit this by sending a high volume of automated registration requests to the device. This can lead to database exhaustion or a denial-of-service (DoS) affecting the availability of the management interface. Acer has indicated that remediation involves implementing request-rate throttling and dynamic validation.

Affected products

  • Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier

Timeline

  • 2026-06-04: disclosed: Initial publication of CVE-2026-50225 and Acer security advisory.

References

Related threats