PT-2026-46141 · Acer · Connect M6E 5G Portable Wifi Router
Ta-Lun Yen
·
Published
2026-06-04
·
Updated
2026-06-04
·
CVE-2026-49186
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connect M6E 5G Portable Wifi Router