Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.5 CVE-2026-50207

Local Modem Manipulation via Binder Interfaces_CVE-2026-50207

The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellu...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.2 CVE-2026-3820

Supermicro BMC’s SMTP service contains a command injection vulnerability_CVE-2026-3820

There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inje...

SMCI AS-2115HS-TNR 01.08.01 CVE
HIGH 8.5 CVE-2026-49189

Broadcast Receiver Privilege Escalation_CVE-2026-49189

Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.7 CVE-2026-49188

Elevated Root Command Execution via ai_cmd Sockets_CVE-2026-49188

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to exe...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.7 CVE-2026-49187

Hard-coded APK Resource Credentials & Scepters_CVE-2026-49187

The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.5 CVE-2026-50206

VPN Command Injection Vulnerability_CVE-2026-50206

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-50205

Plaintext Log Credential Leakage_CVE-2026-50205

System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.2 CVE-2026-49203

Unauthenticated eSIM Configuration Manipulation_CVE-2026-49203

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or del...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-49202

Unverified Meeting Recording Endpoints & Permissive CORS_CVE-2026-49202

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that al...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.7 CVE-2026-49193

Publicly Readable AWS S3 Telemetry Buckets_CVE-2026-49193

Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.

Acer Connect M6E 5G Portable WiFi Router * CVE