CVE-2026-49203: Acer Connect m6e 5g Firmware

High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.

Affected products

  • Acer Connect m6e 5g Firmware: up to and including m6e_ai_1.00.000019

Published 2026-06-04. Last modified 2026-07-22.