CVE-2016-5648: Acer Portal

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.

Affected products

  • Acer Acer Portal: up to and including 3.9.3.2006

Published 2017-06-08. Last modified 2026-06-17.