Vulnerabilities
Vulnerable Software
Acer:  >> Connect M6e 5g Firmware  Security Vulnerabilities
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
CVSS Score
8.5
EPSS Score
0.0
Published
2026-06-04
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
CVSS Score
9.2
EPSS Score
0.0
Published
2026-06-04
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
CVSS Score
9.3
EPSS Score
0.0
Published
2026-06-04
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
CVSS Score
6.9
EPSS Score
0.0
Published
2026-06-04
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-06-04
Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.
CVSS Score
7.1
EPSS Score
0.0
Published
2026-06-04
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
CVSS Score
8.7
EPSS Score
0.0
Published
2026-06-04
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-06-04
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-06-04
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
CVSS Score
9.3
EPSS Score
0.0
Published
2026-06-04


Contact Us

Shodan ® - All rights reserved