Executive brief
The Acer Connect M6E 5G portable router contains a vulnerability in its account registration process that lacks protection against automated bots. This allows malicious actors to use automated scripts to create a massive number of fake accounts, potentially overwhelming the device's database and causing service disruptions. This could lead to a denial-of-service condition where legitimate users are unable to manage their devices or access services.
Technical details
The registration path /v1/account/register in Acer Connect M6E firmware (up to version M6E_AI_1.00.000019) does not implement rate limiting, CAPTCHAs, or other bot mitigation mechanisms. This is classified as a missing authentication for a critical function (CWE-306). A remote, unauthenticated attacker can exploit this by sending a high volume of automated registration requests to the device. This can lead to database exhaustion or a denial-of-service (DoS) affecting the availability of the management interface. Acer has indicated that remediation involves implementing request-rate throttling and dynamic validation.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 or earlier
Timeline
- 2026-06-04: disclosed: Initial publication of CVE-2026-50225 and Acer security advisory.