PT-2026-46150 · Acer · Connect M6E 5G Portable Wifi Router

Ta-Lun Yen

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2026-49192

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-49192

Affected Products

Connect M6E 5G Portable Wifi Router