A

Acer Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Acer products.

11 known CVE vulnerabilities tracked

Critical
6
High
2
Medium
3
Low
0
None
0

Vulnerabilities By Year

Products Affected

All Acer CVEs

CVE-2026-50226
5.3 medium

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.

Connect M6E 5G Firmware Jun 4, 2026
CVE-2026-50225
9.1 critical

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Connect M6E 5G Firmware Jun 4, 2026
CVE-2026-50224
4.9 medium

The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.

Connect M6E 5G Firmware Jun 4, 2026
CVE-2026-50214
9.8 critical

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

Connect M6E 5G Firmware Jun 4, 2026
CVE-2026-49201
9.8 critical

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.

Wave 7 Firmware May 29, 2026
CVE-2026-49200
9.8 critical

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.

Wave 7 Firmware May 29, 2026
CVE-2026-49198
4.9 medium

Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.

Predator Connect W6X Firmware May 29, 2026
CVE-2026-49199
9.8 critical

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

Predator Connect W6X Firmware May 29, 2026
CVE-2026-49197
9.8 critical

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.

Predator Connect W6X Firmware May 29, 2026
CVE-2026-49196
7.2 high

The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands.

Predator Connect W6X Firmware May 29, 2026
CVE-2026-49195
8.8 high

Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.

Predator Connect W6X Firmware May 29, 2026