CRITICAL🇵🇱 Wersja polska

CVE-2026-49190

CVSS 9.4v4.0pub. 2026-06-04upd. 2026-07-22

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.

🤖 AI Analysis
How it works

The system does not properly verify permissions for executing operations for many internal operation codes (opcodes). This results in lack of proper access control, allowing an attacker with basic access (PR:L) to send requests invoking these opcodes without proper authorization. As a result, unauthorized application installation or direct execution of system commands on the device is possible.

Impact

An attacker can gain full control over the device by executing arbitrary system commands or installing unauthorized software, and can also affect the integrity and availability of systems connected to the network served by the device.

Mitigation & patch

Apply patches available from the manufacturer according to references: https://community.acer.com/en/kb/articles/19707

Who is affected

Acer Connect M6E 5G and its firmware — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Acer Connect M6e 5g

    HW
    Acer
    all versions
  • Acer Connect M6e 5g Firmware

    OS
    Acer
    ≤ m6e_ai_1.00.000019
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-49194CRITICAL9.4PL ✓same product

Acer Connect M6E 5G — pominięcie uwierzytelnienia przez procedurę debugowania

CVE-2026-50208CRITICAL9.2PL ✓same product

Acer Connect M6E 5G: wyłączona walidacja TLS i zakodowane klucze DES umożliwiają MITM

CVE-2026-49185CRITICAL10.0PL ✓same product

Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging

CVE-2026-49191CRITICAL9.3PL ✓same product

Acer Connect M6E 5G — hardkodowane klucze API w M3WebServer (Auth Bypass)

CVE-2026-50209CRITICAL9.3PL ✓same product

Acer Connect M6E 5G – przejęcie kontroli MDM przez broadcast event