Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://community.acer.com/en/kb/articles/19707 |
|
Mon, 08 Jun 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acer connect M6e 5g
Acer connect M6e 5g Firmware |
|
| CPEs | cpe:2.3:h:acer:connect_m6e_5g:-:*:*:*:*:*:*:* cpe:2.3:o:acer:connect_m6e_5g_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Acer connect M6e 5g
Acer connect M6e 5g Firmware |
|
| Metrics |
cvssV3_1
|
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acer
Acer connect M6e 5g Portable Wifi Router |
|
| Vendors & Products |
Acer
Acer connect M6e 5g Portable Wifi Router |
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links. | |
| Title | Firmware Theft & IMEI Spoofing via Connect-OTA | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Acer
Published:
Updated: 2026-06-04T12:21:50.502Z
Reserved: 2026-06-04T09:22:14.582Z
Link: CVE-2026-50226
Updated: 2026-06-04T12:21:45.769Z
Status : Analyzed
Published: 2026-06-04T10:16:40.247
Modified: 2026-06-08T12:57:32.277
Link: CVE-2026-50226
No data.
OpenCVE Enrichment
Updated: 2026-06-05T10:08:35Z