The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
The production version of M3WebServer contains hardcoded backend API keys that are not removed or obfuscated before deployment. These keys can be intercepted by an attacker through error handling pages, which in verbose mode reveal detailed diagnostic information. Obtaining these keys allows the attacker to authenticate against the API without knowing the correct user credentials.
A remote unauthenticated attacker can gain full access to the device's API interface, leading to breaches of confidentiality, integrity, and availability of the system (high risk in all three categories according to CVSS vector).
Apply patches available from the manufacturer in accordance with the references (https://community.acer.com/en/kb/articles/19707). Until the update is applied, it is recommended to restrict access to the device's administrative interface only to trusted networks and disable exposure of the management panel to the public network.
Acer Connect M6E 5G and its corresponding firmware (Acer Connect M6E 5G Firmware) — specific versions indicated in the manufacturer's references
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAcer Connect M6e 5g
HWAcerall versionsAcer Connect M6e 5g Firmware
OSAcer≤ m6e_ai_1.00.000019
Related vulnerabilities
Acer Connect M6E 5G — pominięcie uwierzytelnienia przez procedurę debugowania
Acer Connect M6E 5G: wyłączona walidacja TLS i zakodowane klucze DES umożliwiają MITM
Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging
Command injection w Acer Connect M6E 5G — nieautoryzowane wykonanie poleceń
Acer Connect M6E 5G – przejęcie kontroli MDM przez broadcast event