The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
A debug procedure named SCREEN_CLICK with parameter 5053 is present in the device firmware. Invoking this procedure causes the established connection to bypass the standard authentication mechanism (login prompt) and gain direct access to an interactive shell. This mechanism likely remained in production firmware as an unintended artifact of the development or testing process.
An attacker with network access and basic privileges can gain full control over the device through an interactive shell, enabling configuration modification, network traffic interception, and potential exploitation of the device as an entry point to the internal network.
Apply patches available from the manufacturer according to the references (https://community.acer.com/en/kb/articles/19707). Until the update is applied, it is recommended to restrict access to the device management interface only to trusted hosts and implement network segmentation.
Acer Connect M6E 5G Firmware and Acer Connect M6E 5G device — specific firmware versions indicated in the manufacturer's references.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAcer Connect M6e 5g
HWAcerall versionsAcer Connect M6e 5g Firmware
OSAcer≤ m6e_ai_1.00.000019
Related vulnerabilities
Acer Connect M6E 5G — hardkodowane klucze API w M3WebServer (Auth Bypass)
Acer Connect M6E 5G: wyłączona walidacja TLS i zakodowane klucze DES umożliwiają MITM
Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging
Command injection w Acer Connect M6E 5G — nieautoryzowane wykonanie poleceń
Acer Connect M6E 5G – przejęcie kontroli MDM przez broadcast event