CRITICAL🇵🇱 Wersja polska

CVE-2026-49194

CVSS 9.4v4.0pub. 2026-06-04upd. 2026-07-22

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.

🤖 AI Analysis
How it works

A debug procedure named SCREEN_CLICK with parameter 5053 is present in the device firmware. Invoking this procedure causes the established connection to bypass the standard authentication mechanism (login prompt) and gain direct access to an interactive shell. This mechanism likely remained in production firmware as an unintended artifact of the development or testing process.

Impact

An attacker with network access and basic privileges can gain full control over the device through an interactive shell, enabling configuration modification, network traffic interception, and potential exploitation of the device as an entry point to the internal network.

Mitigation & patch

Apply patches available from the manufacturer according to the references (https://community.acer.com/en/kb/articles/19707). Until the update is applied, it is recommended to restrict access to the device management interface only to trusted hosts and implement network segmentation.

Who is affected

Acer Connect M6E 5G Firmware and Acer Connect M6E 5G device — specific firmware versions indicated in the manufacturer's references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Acer Connect M6e 5g

    HW
    Acer
    all versions
  • Acer Connect M6e 5g Firmware

    OS
    Acer
    ≤ m6e_ai_1.00.000019
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-49191CRITICAL9.3PL ✓same product

Acer Connect M6E 5G — hardkodowane klucze API w M3WebServer (Auth Bypass)

CVE-2026-50208CRITICAL9.2PL ✓same product

Acer Connect M6E 5G: wyłączona walidacja TLS i zakodowane klucze DES umożliwiają MITM

CVE-2026-49185CRITICAL10.0PL ✓same product

Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging

CVE-2026-49190CRITICAL9.4PL ✓same product

Command injection w Acer Connect M6E 5G — nieautoryzowane wykonanie poleceń

CVE-2026-50209CRITICAL9.3PL ✓same product

Acer Connect M6E 5G – przejęcie kontroli MDM przez broadcast event