Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.2 CVE-2026-49203

Unauthenticated eSIM Configuration Manipulation_CVE-2026-49203

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or del...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-49202

Unverified Meeting Recording Endpoints & Permissive CORS_CVE-2026-49202

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that al...

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.4 CVE-2026-49194

SCREEN_CLICK Authentication Bypass_CVE-2026-49194

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive s...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.7 CVE-2026-49193

Publicly Readable AWS S3 Telemetry Buckets_CVE-2026-49193

Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 5.3 CVE-2026-49192

Summary Service Insecure Direct Object Reference_CVE-2026-49192

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device...

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.3 CVE-2026-49191

Exposed Hard-coded M3WebServer Backend API Key_CVE-2026-49191

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.4 CVE-2026-49190

Missing Per-Instruction Authorization Checks_CVE-2026-49190

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application instal...

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 5.8 CVE-2026-46447

CVE-2026-46447_CVE-2026-46447

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

OpenStack Ironic 17.0.0 CVE
HIGH 8.6 CVE-2026-49186

Lack of MQTT Broker Topic Access Control Lists_CVE-2026-49186

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or...

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 10 CVE-2026-49185

Instruction Injection via FieldX MDM_CVE-2026-49185

The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

Acer Connect M6E 5G Portable WiFi Router * CVE