CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries...Show more |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 8.8 HIGH· v4 9.1 CRITICAL· v3 N/A· v2 The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 6.9 MEDIUM· v4 4.9 MEDIUM· v3 N/A· v2 The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans. |
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings. |
Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 8.8 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers. |
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 9.3 CRITICAL· v4 7.8 HIGH· v3 N/A· v2 Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 9.2 CRITICAL· v4 9.4 CRITICAL· v3 N/A· v2 High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic. |
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity. |
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files. |
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 6.9 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. |
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted. |
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 9.4 CRITICAL· v4 8.8 HIGH· v3 N/A· v2 The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface. |
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 5.3 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages. |