Acer
acer
53 CVEs • 116 products
Products (116)
Click to collapseToggle
Products (116)
Click to collapse
CVEs (53)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 9.4 CRITICAL· v4 8.8 HIGH· v3 N/A· v2 The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions. |
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 8.7 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands. |
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse. |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 8.6 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands...Show more |
1Acer 1Connect M6e 5g Firmware Jul 22, 2026 Jun 4, 2026 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection. |
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injec...Show more |
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access. |
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. |
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 8.3 HIGH· v4 4.9 MEDIUM· v3 N/A· v2 Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors. |
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails. |
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands. |
1Acer 1Predator Connect W6x Firmware Jul 21, 2026 May 29, 2026 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands. |
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a...Show more |
An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject arbitrary keystrokes via use of weak encryption. |
Stack overflow vulnerability in Aspire E5-475G 's BIOS firmware, in the FpGui module, a second call to GetVariable services allows local attackers to execute arbitrary code in the UEFI DXE phase and gain escalated privil...Show more |
1Acer 5Aspire A115 21 Firmware Aspire A315 22 FirmwareAspire A315 22g Firmware+2 moreJun 17, 2026 Nov 28, 2022 N/A· v4 8.2 HIGH· v3 N/A· v2 Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.
|
1Acer 1Altos W2000h W570h F4 Firmware Jul 9, 2026 Oct 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into...Show more |
1Acer 34Altos T110 F3 Firmware Ap130 F2 FirmwareAspire 1600x Firmware+31 moreJul 9, 2026 Sep 23, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring...Show more |
Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority through a named pipe. In th...Show more |