LIVE · cybersecurity feed
Live wire
vendor

Acer

26 CVEs published in the last four months. Exploited flaws first.

Critical12
High14
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-492019.8criticalwave 7 firmwareThe upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key.99d ago
CVE-2026-491979.8criticalpredator connect w6x firmwareWeb endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to bloc99d ago
CVE-2026-491999.8criticalpredator connect w6x firmwareCrafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.99d ago
CVE-2026-502149.8criticalconnect m6e 5g firmwareThe /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arb93d ago
CVE-2026-502119.8criticalconnect m6e 5g firmwareLeftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving mal93d ago
CVE-2026-491919.8criticalconnect m6e 5g firmwareThe production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through v93d ago
CVE-2026-491889.8criticalconnect m6e 5g firmwareThe ai_cmd utility executes with full root permissions.93d ago
CVE-2026-491859.8criticalconnect m6e 5g firmwareThe FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instr93d ago
CVE-2026-492009.8criticalwave 7 firmwareThe acer_cgi.log file in the device firmware is accessible without authentication via the web interface.99d ago
CVE-2026-491869.8criticalconnect m6e 5g firmwareThe local MQTT broker does not enforce topic-level Access Control Lists (ACLs).93d ago
CVE-2026-502089.4criticalconnect m6e 5g firmwareHigh-risk TrustAllCerts routines disable standard TLS certificate validation.93d ago
CVE-2026-502259.1criticalconnect m6e 5g firmwareThe registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated sys93d ago
CVE-2026-491958.8highpredator connect w6x firmwareUnauthenticated Debug Service.99d ago
CVE-2026-491948.8highconnect m6e 5g firmwareThe debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely an93d ago
CVE-2026-491908.8highconnect m6e 5g firmwareThe system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permittin93d ago
CVE-2026-492028.6highconnect m6e 5g firmwareInternal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Reso93d ago
CVE-2026-492038.3highconnect m6e 5g firmwareCrucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remot93d ago
CVE-2026-502058.2highconnect m6e 5g firmwareSystem log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate id93d ago
CVE-2026-502097.8highconnect m6e 5g firmwareBroadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint 93d ago
CVE-2026-502077.8highconnect m6e 5g firmwareThe system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to rea93d ago
CVE-2026-491897.8highconnect m6e 5g firmwareUnchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to i93d ago
CVE-2026-491937.5highconnect m6e 5g firmwareOverly permissive configuration settings on cloud storage containers expose active telemetry information publicly 93d ago
CVE-2026-491877.5highconnect m6e 5g firmwareThe hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential mi93d ago
CVE-2026-502107.5highconnect m6e 5g firmwareThe device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible93d ago
CVE-2026-502137.5highconnect m6e 5g firmwareThe account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be cra93d ago
CVE-2026-491967.2highpredator connect w6x firmwareThe Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitra99d ago

Filter the full tracker by Acer