VYPR

Vendor CVEs

Acer

All CVEs

72 total · sorted by risk
  • CVE-2026-49204MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

  • CVE-2023-48034MedNov 27, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject arbitrary keystrokes via use of weak encryption.

  • CVE-2026-9490MedMay 25, 2026
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe,…

  • CVE-2026-49192MedJun 4, 2026
    risk 0.35cvss 5.4epss 0.00

    The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

  • CVE-2016-5648MedJun 8, 2017
    risk 0.35cvss 5.3epss 0.01

    Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.

  • CVE-2026-50226MedJun 4, 2026
    risk 0.34cvss 5.3epss 0.00

    Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.

  • CVE-2026-50604MedSep 17, 2026
    risk 0.32cvss —epss 0.00

    A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized…

  • CVE-2026-50603MedSep 17, 2026
    risk 0.32cvss —epss 0.00

    A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the…

  • CVE-2026-50224MedJun 4, 2026
    risk 0.32cvss 4.9epss 0.00

    The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.

  • CVE-2026-49198MedMay 29, 2026
    risk 0.32cvss 4.9epss 0.00

    Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.

  • CVE-2026-50607LowSep 17, 2026
    risk 0.18cvss —epss 0.00

    A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended network access.

  • CVE-2026-50608LowSep 17, 2026
    risk 0.08cvss —epss 0.00

    A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized…

  • CVE-2026-50606LowSep 17, 2026
    risk 0.08cvss —epss 0.00

    A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use…

  • CVE-2006-6121Nov 26, 2006
    risk 0.04cvss —epss 0.12

    Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method.

  • CVE-2012-3290Jun 7, 2012
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Series 5, 5 550, and Chromebox 3; and Cr-48 Chromebook platforms have unknown impact and attack vectors.

  • CVE-2012-1418Feb 29, 2012
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

  • CVE-2012-0695Jan 12, 2012
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

  • CVE-2011-4719Dec 9, 2011
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

  • CVE-2011-4548Nov 24, 2011
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

  • CVE-2011-3421Sep 12, 2011
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.125 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

  • CVE-2011-3420Sep 12, 2011
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.

  • CVE-2009-2627Aug 19, 2009
    risk 0.00cvss —epss 0.05

    Insecure method vulnerability in the Acer LunchApp (aka AcerCtrls.APlunch) ActiveX control in acerctrl.ocx allows remote attackers to execute arbitrary commands via the Run method, a different vulnerability than CVE-2006-6121.

Page 2 of 2