CVE-2026-49192
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 8fc372e3-d9c5-46e4-9410-38469745c639 (Secondary)
Description
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
Affected (1)
Products: Acer: Connect M6e 5g Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to m6e_ai_1.00.000019 |
| Running on/with | Platform Versions |
|---|---|
Acer Connect M6e 5g | All versions |
References (1)
Source: 8fc372e3-d9c5-46e4-9410-38469745c639
MitigationVendor Advisory
Timeline
No history available yet.