API Token Vulnerability in Acer Network Management Services
CVE-2026-50214
9.3CRITICAL
What is CVE-2026-50214?
The /v1/Plan service provided by Acer relies on a single global API token for complete administrative control. This design flaw permits unauthorized users to create zero-cost network access plans, leading to significant security risks. Attackers can exploit this vulnerability to gain full administrative privileges and manipulate network configurations without proper authorization.
Affected Version(s)
Connect M6E 5G Portable WiFi Router *
