Exposed Debug Modules in Acer Products Risk AWS Cognito Exploitation
CVE-2026-49204

6.9MEDIUM

Key Information:

Vendor

Acer

Vendor
CVE Published:
4 June 2026

What is CVE-2026-49204?

The vulnerability arises from leftover debug modules in multiple Acer products that contain hard-coded credentials for internal AWS Cognito test environments. These exposed credentials create a risk of unauthorized access and potential exploitation of sensitive assets. Organizations using affected Acer devices should take immediate action to mitigate the risk by updating their products and removing any unnecessary debug tools.

Affected Version(s)

Connect M6E 5G Portable WiFi Router *

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ta-Lun Yen
.