Executive brief
The AcerConnect Over-the-Air (OTA) application, used by Acer portable routers to receive software updates, contains hard-coded security keys. An attacker can use these keys to impersonate any device and gain unauthorized access to the manufacturer's update catalog. This could allow an attacker to download protected firmware binaries and potentially gain insights into the device's internal software.
Technical details
The AcerConnect OTA application contains hard-coded AES-128-CBC cryptographic keys (CWE-321). Because these keys are static across the product line, a remote attacker can use them to generate valid authorization credentials for any arbitrary IMEI number. This bypasses intended access controls, allowing the attacker to query the update catalog and retrieve protected firmware binaries via pre-signed cloud links. Acer is addressing this by transitioning to dynamic, per-device credential issuance.
Affected products
- Acer Connect M6E 5G Portable WiFi Router M6E_AI_1.00.000019 and earlier
Timeline
- 2026-06-04: disclosed: Initial publication of CVE-2026-50226
- 2026-06-04: advisory: Acer published security advisory 19707