The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
The system does not properly verify permissions for executing operations for many internal operation codes (opcodes). This results in lack of proper access control, allowing an attacker with basic access (PR:L) to send requests invoking these opcodes without proper authorization. As a result, unauthorized application installation or direct execution of system commands on the device is possible.
An attacker can gain full control over the device by executing arbitrary system commands or installing unauthorized software, and can also affect the integrity and availability of systems connected to the network served by the device.
Apply patches available from the manufacturer according to references: https://community.acer.com/en/kb/articles/19707
Acer Connect M6E 5G and its firmware — versions indicated in the manufacturer's references
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAcer Connect M6e 5g
HWAcerall versionsAcer Connect M6e 5g Firmware
OSAcer≤ m6e_ai_1.00.000019
Related vulnerabilities
Acer Connect M6E 5G — pominięcie uwierzytelnienia przez procedurę debugowania
Acer Connect M6E 5G: wyłączona walidacja TLS i zakodowane klucze DES umożliwiają MITM
Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging
Acer Connect M6E 5G — hardkodowane klucze API w M3WebServer (Auth Bypass)
Acer Connect M6E 5G – przejęcie kontroli MDM przez broadcast event