VYPR

Connect M6e 5g Firmware

by Acer

CVEs (26)

  • CVE-2026-50206MedJun 4, 2026
    risk 0.44cvss 6.8epss 0.01

    Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

  • CVE-2026-50212MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.

  • CVE-2026-49204MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

  • CVE-2026-49192MedJun 4, 2026
    risk 0.35cvss 5.4epss 0.00

    The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

  • CVE-2026-50226MedJun 4, 2026
    risk 0.34cvss 5.3epss 0.00

    Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.

  • CVE-2026-50224MedJun 4, 2026
    risk 0.32cvss 4.9epss 0.00

    The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.

Page 2 of 2