High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
The device firmware contains dangerous TrustAllCerts routines that completely bypass TLS certificate verification — this makes it impossible to detect fake or untrusted certificates during network communication. At the same time, symmetric DES encryption keys are hardcoded into the firmware code (CWE-330: use of insufficiently random values). The combination of both weaknesses means that an attacker in a Man-in-the-Middle position can not only intercept the TLS session but also decrypt transmitted data using the known DES keys.
An attacker in a Man-in-the-Middle position can decrypt and read sensitive network traffic passing through the device, resulting in a breach of data confidentiality and integrity for the user.
Apply patches available from the manufacturer according to the references (https://community.acer.com/en/kb/articles/19707). Network segmentation, limiting device exposure to untrusted networks, and monitoring network traffic until updates are deployed are also recommended.
Acer Connect M6E 5G and Acer Connect M6E 5G Firmware — specific versions indicated in the manufacturer's references.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAcer Connect M6e 5g
HWAcerall versionsAcer Connect M6e 5g Firmware
OSAcer≤ m6e_ai_1.00.000019
Related vulnerabilities
Acer Connect M6E 5G — hardkodowane klucze API w M3WebServer (Auth Bypass)
Acer Connect M6E 5G — pominięcie uwierzytelnienia przez procedurę debugowania
Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging
Command injection w Acer Connect M6E 5G — nieautoryzowane wykonanie poleceń
Acer Connect M6E 5G – przejęcie kontroli MDM przez broadcast event