Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
An application with local user privileges can send broadcast events that are handled by the system without proper permission verification. Insufficient access control to these events allows malicious software to write a new MDM endpoint address. As a result, the device begins reporting to a server controlled by the attacker instead of the legitimate administrator.
An attacker can take full administrative control of the device, managing it through their own MDM server, which includes high confidentiality, integrity, and availability impacts on both the system and associated resources.
Apply patches available from the manufacturer according to the references: https://community.acer.com/en/kb/articles/19707
Acer Connect M6E 5G and its firmware software (Acer Connect M6E 5G Firmware) — specific versions indicated in the manufacturer's references.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XAcer Connect M6e 5g
HWAcerall versionsAcer Connect M6e 5g Firmware
OSAcer≤ m6e_ai_1.00.000019
Related vulnerabilities
Acer Connect M6E 5G — hardkodowane klucze API w M3WebServer (Auth Bypass)
Acer Connect M6E 5G — pominięcie uwierzytelnienia przez procedurę debugowania
Command injection w Acer Connect M6E 5G via FieldX MDM adb messaging
Command injection w Acer Connect M6E 5G — nieautoryzowane wykonanie poleceń
Acer Connect M6E 5G: wyłączona walidacja TLS i zakodowane klucze DES umożliwiają MITM