| CVE-2026-49201 | 9.8 | critical | wave 7 firmware | The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. | 99d ago |
| CVE-2026-49197 | 9.8 | critical | predator connect w6x firmware | Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to bloc | 99d ago |
| CVE-2026-49199 | 9.8 | critical | predator connect w6x firmware | Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. | 99d ago |
| CVE-2026-50214 | 9.8 | critical | connect m6e 5g firmware | The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arb | 93d ago |
| CVE-2026-50211 | 9.8 | critical | connect m6e 5g firmware | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving mal | 93d ago |
| CVE-2026-49191 | 9.8 | critical | connect m6e 5g firmware | The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through v | 93d ago |
| CVE-2026-49188 | 9.8 | critical | connect m6e 5g firmware | The ai_cmd utility executes with full root permissions. | 93d ago |
| CVE-2026-49185 | 9.8 | critical | connect m6e 5g firmware | The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instr | 93d ago |
| CVE-2026-49200 | 9.8 | critical | wave 7 firmware | The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. | 99d ago |
| CVE-2026-49186 | 9.8 | critical | connect m6e 5g firmware | The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). | 93d ago |
| CVE-2026-50208 | 9.4 | critical | connect m6e 5g firmware | High-risk TrustAllCerts routines disable standard TLS certificate validation. | 93d ago |
| CVE-2026-50225 | 9.1 | critical | connect m6e 5g firmware | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated sys | 93d ago |
| CVE-2026-49195 | 8.8 | high | predator connect w6x firmware | Unauthenticated Debug Service. | 99d ago |
| CVE-2026-49194 | 8.8 | high | connect m6e 5g firmware | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely an | 93d ago |
| CVE-2026-49190 | 8.8 | high | connect m6e 5g firmware | The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permittin | 93d ago |
| CVE-2026-49202 | 8.6 | high | connect m6e 5g firmware | Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Reso | 93d ago |
| CVE-2026-49203 | 8.3 | high | connect m6e 5g firmware | Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remot | 93d ago |
| CVE-2026-50205 | 8.2 | high | connect m6e 5g firmware | System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate id | 93d ago |
| CVE-2026-50209 | 7.8 | high | connect m6e 5g firmware | Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint | 93d ago |
| CVE-2026-50207 | 7.8 | high | connect m6e 5g firmware | The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to rea | 93d ago |
| CVE-2026-49189 | 7.8 | high | connect m6e 5g firmware | Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to i | 93d ago |
| CVE-2026-49193 | 7.5 | high | connect m6e 5g firmware | Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly | 93d ago |
| CVE-2026-49187 | 7.5 | high | connect m6e 5g firmware | The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential mi | 93d ago |
| CVE-2026-50210 | 7.5 | high | connect m6e 5g firmware | The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible | 93d ago |
| CVE-2026-50213 | 7.5 | high | connect m6e 5g firmware | The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be cra | 93d ago |
| CVE-2026-49196 | 7.2 | high | predator connect w6x firmware | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitra | 99d ago |