VYPR

AcerConnect OTA

by Acer

CVEs (1)

  • CVE-2026-50226MedJun 4, 2026
    risk 0.45cvss epss

    Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.