CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. |
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 8.3 HIGH· v4 4.9 MEDIUM· v3 N/A· v2 Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors. |
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails. |
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands. |
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands. |