Acer M6E是中国台湾宏碁(Acer)公司的一款便携式5G移动热点设备。 Acer M6E存在安全漏洞,该漏洞源于ai_cmd工具以完全root权限执行,并将套接字输入直接传递给popen,可能导致未经身份验证的用户执行任意root命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Acer | Connect M6E 5G Portable WiFi Router | *≤ M6E_AI_1.00.000019 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Acer | Connect M6E 5G Portable WiFi Router | * ~ M6E_AI_1.00.000019 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50224 | Unauthenticated IPv6 WAN Management Exposure | |
| CVE-2026-50206 | VPN Command Injection Vulnerability | |
| CVE-2026-50205 | Plaintext Log Credential Leakage | |
| CVE-2026-50207 | Local Modem Manipulation via Binder Interfaces | |
| CVE-2026-50226 | Firmware Theft & IMEI Spoofing via Connect-OTA | |
| CVE-2026-50225 | Account Creation Exhaustion | |
| CVE-2026-50212 | Arbitrary Remote Device Unbinding | |
| CVE-2026-50211 | Exposed Factory Testing App Boundaries | |
| CVE-2026-50209 | MDM Server Registration Overriding | |
| CVE-2026-50210 | Weak Static Cryptographic Initialization Vectors | |
| CVE-2026-50213 | Bulk User Private Data Harvesting | |
| CVE-2026-50208 | Permissive TrustAllCerts TLS Verification | |
| CVE-2026-50214 | Shared Secret Quota Inflation | |
| CVE-2026-49204 | Hard-coded AWS Cognito Testing Accounts | |
| CVE-2026-49186 | Lack of MQTT Broker Topic Access Control Lists | |
| CVE-2026-49191 | Exposed Hard-coded M3WebServer Backend API Key | |
| CVE-2026-49189 | Broadcast Receiver Privilege Escalation | |
| CVE-2026-49190 | Missing Per-Instruction Authorization Checks | |
| CVE-2026-49192 | Summary Service Insecure Direct Object Reference | |
| CVE-2026-49202 | Unverified Meeting Recording Endpoints & Permissive CORS |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet