CRITICAL🇵🇱 Wersja polska

CVE-2026-49191

CVSS 9.3v4.0pub. 2026-06-04upd. 2026-07-22

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

🤖 AI Analysis
How it works

The production version of M3WebServer contains hardcoded backend API keys that are not removed or obfuscated before deployment. These keys can be intercepted by an attacker through error handling pages, which in verbose mode reveal detailed diagnostic information. Obtaining these keys allows the attacker to authenticate against the API without knowing the correct user credentials.

Impact

A remote unauthenticated attacker can gain full access to the device's API interface, leading to breaches of confidentiality, integrity, and availability of the system (high risk in all three categories according to CVSS vector).

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references (https://community.acer.com/en/kb/articles/19707). Until the update is applied, it is recommended to restrict access to the device's administrative interface only to trusted networks and disable exposure of the management panel to the public network.

Who is affected

Acer Connect M6E 5G and its corresponding firmware (Acer Connect M6E 5G Firmware) — specific versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Acer Connect M6e 5g

    HW
    Acer
    all versions
  • Acer Connect M6e 5g Firmware

    OS
    Acer
    ≤ m6e_ai_1.00.000019
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-49194CRITICAL9.4PL ✓same product

Acer Connect M6E 5G — pominięcie uwierzytelnienia przez procedurę debugowania

CVE-2026-50208CRITICAL9.2PL ✓same product

Acer Connect M6E 5G: wyłączona walidacja TLS i zakodowane klucze DES umożliwiają MITM

CVE-2026-49185CRITICAL10.0PL ✓same product

Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging

CVE-2026-49190CRITICAL9.4PL ✓same product

Command injection w Acer Connect M6E 5G — nieautoryzowane wykonanie poleceń

CVE-2026-50209CRITICAL9.3PL ✓same product

Acer Connect M6E 5G – przejęcie kontroli MDM przez broadcast event