CVE-2026-49192: Acer Connect m6e 5g Firmware
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
Affected products
- Acer Connect m6e 5g Firmware: up to and including m6e_ai_1.00.000019
Published 2026-06-04. Last modified 2026-07-22.