Security Flaw in Web Administration Panel of Acer Products
CVE-2026-50224

6.9MEDIUM

Key Information:

Vendor

Acer

Vendor
CVE Published:
4 June 2026

What is CVE-2026-50224?

Acer's web administration panel is susceptible to a security issue where it binds openly to the public IPv6 address on port [::]:8080. This configuration permits external access to internal API endpoints, thereby increasing the risk of unauthorized access and potential exploitation by attackers over the WAN.

Affected Version(s)

Connect M6E 5G Portable WiFi Router *

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ta-Lun Yen
.