CVE-2026-49192

MEDIUM

Acer Connect M6E 5G Portable WiFi Router - Summary Service Insecure Direct Object Reference

Title source: rule
STIX 2.1

Description

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
Acer/Connect M6E 5G Portable WiFi Router < M6E_AI_1.00.000019
acer/connect_m6e_5g_firmware < m6e_ai_1.00.000019
Published Jun 04, 2026
Tracked Since Jun 04, 2026