📦

connect_m6e_5g

Vendor: acer

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 3 Remote Access
Total CVEs 52 Total Indexed
Avg. EPSS 0.43% Exploit Prob.
Latest CVE CVE-2026-50226 Jun 04

Security Vulnerability Index

Page 1 / 6
6.9 CVSS

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.

EPSS: 0.31%
8.8 CVSS

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

EPSS: 0.44%
6.9 CVSS

The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.

EPSS: 0.40%
9.3 CVSS

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

EPSS: 0.25%
8.7 CVSS

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.

EPSS: 0.39%
7.1 CVSS

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.

EPSS: 0.27%
8.8 CVSS

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.

EPSS: 0.52%
6.9 CVSS

The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.

EPSS: 0.42%
9.3 CVSS

Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.

EPSS: 0.14%
9.2 CVSS

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.

EPSS: 0.24%