Root Command Execution Vulnerability in Acer Utility
CVE-2026-49188
8.7HIGH
What is CVE-2026-49188?
The ai_cmd utility from Acer is susceptible to a command execution vulnerability that allows unauthenticated users to execute arbitrary commands with root privileges. This is achieved through its use of socket inputs piped directly to popen(), creating a significant security risk. Without proper restrictions, this vulnerability could be exploited to gain unauthorized access to system-level commands and resources, potentially leading to severe consequences for affected systems.
Affected Version(s)
Connect M6E 5G Portable WiFi Router *
