Command Injection Vulnerability in Acer VPN Configuration Settings
CVE-2026-50206

8.5HIGH

Key Information:

Vendor

Acer

Vendor
CVE Published:
4 June 2026

What is CVE-2026-50206?

A vulnerability exists in Acer's VPN network profile settings where the processing of special characters is inadequate. This flaw can allow an attacker to exploit the system by injecting malicious commands through improperly handled configuration files. As a result, users may be at risk of unauthorized access and control over their systems. It is essential for users to remain vigilant and ensure their VPN configurations are secure.

Affected Version(s)

Connect M6E 5G Portable WiFi Router *

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ta-Lun Yen
.