← Back

Connect M6e 5g Firmware

connect_m6e_5g_firmware

Vendor: Acer • 26 CVEs

CVEs (26)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Acer
1Connect M6e 5g Firmware
Jul 22, 2026
Jun 4, 2026
9.4 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
1Acer
1Connect M6e 5g Firmware
Jul 22, 2026
Jun 4, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
1Acer
1Connect M6e 5g Firmware
Jul 22, 2026
Jun 4, 2026
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
1Acer
1Connect M6e 5g Firmware
Jul 22, 2026
Jun 4, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
1Acer
1Connect M6e 5g Firmware
Jul 22, 2026
Jun 4, 2026
8.6 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands...Show more
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.Show less
1Acer
1Connect M6e 5g Firmware
Jul 22, 2026
Jun 4, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.