← Vulnerability feed

Vulnerability record · CVE-2026-50213 · published 4 June 2026

CVE-2026-50213: Acer connect m6e 5g firmware hard-coded credentials vulnerability

Acer · Connect M6e 5g Firmware

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.

8.7 CVSS 4.0 High EPSS 0.39% · top 69.1% CWE-798 · Hard-coded credentials
8.7CVSS 4.0 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Jul 2026Last modified by NVD

Description

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://community.acer.com/en/kb/articles/19707 MitigationVendor Advisory

Track CVE-2026-50213 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-49185Acer connect m6e 5g firmware os command injection vulnerabilityThe FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.EPSS 0.56%9.4CVE-2026-49194Acer connect m6e 5g firmware improper authentication vulnerabilityThe debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive she…EPSS 0.42%9.4CVE-2026-49190Acer connect m6e 5g firmware os command injection vulnerabilityThe system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installa…EPSS 0.81%9.3CVE-2026-50214Acer connect m6e 5g firmware insufficient verification of data authenticity vulnerabilityThe /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost networ…EPSS 0.25%9.3CVE-2026-50209Acer connect m6e 5g firmware incorrect permission assignment vulnerabilityBroadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ow…EPSS 0.14%9.3CVE-2026-49191Acer connect m6e 5g firmware improper authentication vulnerabilityThe production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.EPSS 0.53%9.2CVE-2026-50208Acer connect m6e 5g firmware vulnerabilityHigh-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Mi…EPSS 0.24%8.8CVE-2026-50225Acer connect m6e 5g firmware missing authentication for critical function vulnerabilityThe registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2026-50213), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.