Summary Service Insecure Direct Object Reference
CVE-2026-49192

5.3MEDIUM

Key Information:

Vendor

Acer

Vendor
CVE Published:
4 June 2026

What is CVE-2026-49192?

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.

Affected Version(s)

Connect M6E 5G Portable WiFi Router *

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ta-Lun Yen
.