Unauthorized Access Vulnerability in Acer Management API for eSIM Allocation
CVE-2026-49203

7.2HIGH

Key Information:

Vendor

Acer

Vendor
CVE Published:
4 June 2026

What is CVE-2026-49203?

The Acer Management API for cellular eSIM allocation suffers from an authorization issue that allows unauthorized access to crucial management endpoints. This flaw enables malicious users or attackers to remotely rewrite or delete eSIM profiles without proper authentication, potentially leading to significant security risks and privacy breaches for users.

Affected Version(s)

Connect M6E 5G Portable WiFi Router *

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ta-Lun Yen
.