Command Injection Vulnerability in FieldX MDM by Acer
CVE-2026-49185

10CRITICAL

Key Information:

Vendor

Acer

Vendor
CVE Published:
4 June 2026

What is CVE-2026-49185?

The FieldX MDM product developed by Acer is susceptible to a command injection vulnerability due to improper handling of unverified payloads within the adb messaging topic. This flaw allows attackers to potentially execute arbitrary commands through Runtime.exec(), posing significant risks to system integrity and data confidentiality.

Affected Version(s)

Connect M6E 5G Portable WiFi Router *

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ta-Lun Yen
.