CRITICAL🇵🇱 Wersja polska

CVE-2026-50209

CVSS 9.3v4.0pub. 2026-06-04upd. 2026-07-22

Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.

🤖 AI Analysis
How it works

An application with local user privileges can send broadcast events that are handled by the system without proper permission verification. Insufficient access control to these events allows malicious software to write a new MDM endpoint address. As a result, the device begins reporting to a server controlled by the attacker instead of the legitimate administrator.

Impact

An attacker can take full administrative control of the device, managing it through their own MDM server, which includes high confidentiality, integrity, and availability impacts on both the system and associated resources.

Mitigation & patch

Apply patches available from the manufacturer according to the references: https://community.acer.com/en/kb/articles/19707

Who is affected

Acer Connect M6E 5G and its firmware software (Acer Connect M6E 5G Firmware) — specific versions indicated in the manufacturer's references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Acer Connect M6e 5g

    HW
    Acer
    all versions
  • Acer Connect M6e 5g Firmware

    OS
    Acer
    ≤ m6e_ai_1.00.000019
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-49191CRITICAL9.3PL ✓same product

Acer Connect M6E 5G — hardkodowane klucze API w M3WebServer (Auth Bypass)

CVE-2026-49194CRITICAL9.4PL ✓same product

Acer Connect M6E 5G — pominięcie uwierzytelnienia przez procedurę debugowania

CVE-2026-49185CRITICAL10.0PL ✓same product

Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging

CVE-2026-49190CRITICAL9.4PL ✓same product

Command injection w Acer Connect M6E 5G — nieautoryzowane wykonanie poleceń

CVE-2026-50208CRITICAL9.2PL ✓same product

Acer Connect M6E 5G: wyłączona walidacja TLS i zakodowane klucze DES umożliwiają MITM