CVE-2026-50226
Firmware Theft & IMEI Spoofing via Connect-OTA
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.
| CWE | CWE-321 |
| Vendor | acer |
| Product | connect m6e 5g portable wifi router |
| Published | Jun 4, 2026 |
| Last Updated | Jun 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for acer connect m6e 5g portable wifi router
Be the first to know when new unknown vulnerabilities affecting acer connect m6e 5g portable wifi router are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Acer / Connect M6E 5G Portable WiFi Router
* โค M6E_AI_1.00.000019
References
Credits
Ta-Lun Yen