CRITICAL🇵🇱 Wersja polska

CVE-2026-50208

CVSS 9.2v4.0pub. 2026-06-04upd. 2026-07-22

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.

🤖 AI Analysis
How it works

The device firmware contains dangerous TrustAllCerts routines that completely bypass TLS certificate verification — this makes it impossible to detect fake or untrusted certificates during network communication. At the same time, symmetric DES encryption keys are hardcoded into the firmware code (CWE-330: use of insufficiently random values). The combination of both weaknesses means that an attacker in a Man-in-the-Middle position can not only intercept the TLS session but also decrypt transmitted data using the known DES keys.

Impact

An attacker in a Man-in-the-Middle position can decrypt and read sensitive network traffic passing through the device, resulting in a breach of data confidentiality and integrity for the user.

Mitigation & patch

Apply patches available from the manufacturer according to the references (https://community.acer.com/en/kb/articles/19707). Network segmentation, limiting device exposure to untrusted networks, and monitoring network traffic until updates are deployed are also recommended.

Who is affected

Acer Connect M6E 5G and Acer Connect M6E 5G Firmware — specific versions indicated in the manufacturer's references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Acer Connect M6e 5g

    HW
    Acer
    all versions
  • Acer Connect M6e 5g Firmware

    OS
    Acer
    ≤ m6e_ai_1.00.000019
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-49191CRITICAL9.3PL ✓same product

Acer Connect M6E 5G — hardkodowane klucze API w M3WebServer (Auth Bypass)

CVE-2026-49194CRITICAL9.4PL ✓same product

Acer Connect M6E 5G — pominięcie uwierzytelnienia przez procedurę debugowania

CVE-2026-49185CRITICAL10.0PL ✓same product

Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging

CVE-2026-49190CRITICAL9.4PL ✓same product

Command injection w Acer Connect M6E 5G — nieautoryzowane wykonanie poleceń

CVE-2026-50209CRITICAL9.3PL ✓same product

Acer Connect M6E 5G – przejęcie kontroli MDM przez broadcast event