CVE-2026-49203: Acer Connect m6e 5g Firmware
High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
Affected products
- Acer Connect m6e 5g Firmware: up to and including m6e_ai_1.00.000019
Published 2026-06-04. Last modified 2026-07-22.