Vulnerabilities (CVE)

Filtered by vendor Acer Subscribe
Total 56 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-8069 1 Acer 2 Nitrosense, Predatorsense 2026-08-12 N/A 7.8 HIGH
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.
CVE-2026-9490 1 Acer 1 Care Center 2026-07-23 N/A 5.5 MEDIUM
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user to connect and send a specially crafted message (message type 0x03) to the pipe, causing the service to crash with exit code 1067 (ERROR_PROCESS_ABORTED). To mitigate this potential local service disruption, Acer requires users to update the software to the latest version.
CVE-2026-50212 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 6.5 MEDIUM
Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.
CVE-2026-50225 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.1 CRITICAL
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
CVE-2026-49185 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.8 CRITICAL
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
CVE-2026-50207 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.8 HIGH
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
CVE-2026-50211 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.8 CRITICAL
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
CVE-2026-49193 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.5 HIGH
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
CVE-2026-49186 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.8 CRITICAL
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
CVE-2026-49194 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 8.8 HIGH
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
CVE-2026-50210 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.5 HIGH
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
CVE-2026-49188 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.8 CRITICAL
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
CVE-2026-50206 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 6.8 MEDIUM
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
CVE-2026-49191 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.8 CRITICAL
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
CVE-2026-50209 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.8 HIGH
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
CVE-2026-49204 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 6.5 MEDIUM
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
CVE-2026-50226 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 5.3 MEDIUM
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.
CVE-2026-49189 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 7.8 HIGH
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
CVE-2026-50208 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 9.4 CRITICAL
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
CVE-2026-49192 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 5.4 MEDIUM
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.