📦

connect_m6e_5g

Vendor: acer

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 3 Remote Access
Total CVEs 22 Total Indexed
Avg. EPSS 0.04% Exploit Prob.
Latest CVE CVE-2026-50213 Jun 04

Security Vulnerability Index

Page 2 / 3
7.2 CVSS

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.

EPSS: 0.02%
8.8 CVSS

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.

EPSS: 0.06%
9.4 CVSS

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.

EPSS: 0.04%
8.7 CVSS

Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.

EPSS: 0.03%
5.3 CVSS

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

EPSS: 0.03%
9.3 CVSS

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

EPSS: 0.05%
9.4 CVSS

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.

EPSS: 0.06%
8.5 CVSS

Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.

EPSS: 0.01%
8.7 CVSS

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.

EPSS: 0.06%
8.7 CVSS

The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.

EPSS: 0.03%