| CVE-2026-49194 | 8.8 | high | acer / connect m6e 5g firmware | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely an | 93d ago |
| CVE-2026-49190 | 8.8 | high | acer / connect m6e 5g firmware | The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permittin | 93d ago |
| CVE-2026-49195 | 8.8 | high | acer / predator connect w6x firmware | Unauthenticated Debug Service. | 99d ago |
| CVE-2026-49202 | 8.6 | high | acer / connect m6e 5g firmware | Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Reso | 93d ago |
| CVE-2026-49203 | 8.3 | high | acer / connect m6e 5g firmware | Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remot | 93d ago |
| CVE-2026-50205 | 8.2 | high | acer / connect m6e 5g firmware | System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate id | 93d ago |
| CVE-2026-50209 | 7.8 | high | acer / connect m6e 5g firmware | Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint | 93d ago |
| CVE-2026-50207 | 7.8 | high | acer / connect m6e 5g firmware | The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to rea | 93d ago |
| CVE-2026-49189 | 7.8 | high | acer / connect m6e 5g firmware | Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to i | 93d ago |
| CVE-2026-50213 | 7.5 | high | acer / connect m6e 5g firmware | The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be cra | 93d ago |
| CVE-2026-50210 | 7.5 | high | acer / connect m6e 5g firmware | The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible | 93d ago |
| CVE-2026-49193 | 7.5 | high | acer / connect m6e 5g firmware | Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly | 93d ago |
| CVE-2026-49187 | 7.5 | high | acer / connect m6e 5g firmware | The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential mi | 93d ago |
| CVE-2026-49196 | 7.2 | high | acer / predator connect w6x firmware | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitra | 99d ago |