CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 9.4 CRITICAL· v4 8.8 HIGH· v3 N/A· v2 The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions. |
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 8.7 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands. |
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 8.6 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands...Show more |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection. |