| CVE-2026-50214 | 9.8 | critical | acer / connect m6e 5g firmware | The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arb | 93d ago |
| CVE-2026-50211 | 9.8 | critical | acer / connect m6e 5g firmware | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving mal | 93d ago |
| CVE-2026-49191 | 9.8 | critical | acer / connect m6e 5g firmware | The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through v | 93d ago |
| CVE-2026-49188 | 9.8 | critical | acer / connect m6e 5g firmware | The ai_cmd utility executes with full root permissions. | 93d ago |
| CVE-2026-49186 | 9.8 | critical | acer / connect m6e 5g firmware | The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). | 93d ago |
| CVE-2026-49185 | 9.8 | critical | acer / connect m6e 5g firmware | The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instr | 93d ago |
| CVE-2026-49201 | 9.8 | critical | acer / wave 7 firmware | The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. | 99d ago |
| CVE-2026-49200 | 9.8 | critical | acer / wave 7 firmware | The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. | 99d ago |
| CVE-2026-49199 | 9.8 | critical | acer / predator connect w6x firmware | Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. | 99d ago |
| CVE-2026-49197 | 9.8 | critical | acer / predator connect w6x firmware | Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to bloc | 99d ago |
| CVE-2026-50208 | 9.4 | critical | acer / connect m6e 5g firmware | High-risk TrustAllCerts routines disable standard TLS certificate validation. | 93d ago |
| CVE-2026-50225 | 9.1 | critical | acer / connect m6e 5g firmware | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated sys | 93d ago |