Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connect M6e 5g Firmware CRITICAL 9.1
CVE-2026-50225

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware MEDIUM 5.3
CVE-2026-50226

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows u…

Mitigation only
Fix from $1,600 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-50214

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost networ…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-50211

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to int…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.4
CVE-2026-50208

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Mi…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware HIGH 7.8
CVE-2026-50207

The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellula…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 7.8
CVE-2026-50209

Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ow…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 7.5
CVE-2026-50210

The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaint…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 7.5
CVE-2026-50213

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable ident…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware MEDIUM 6.5
CVE-2026-50212

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe de…

Mitigation only
Fix from $1,600 2026-06-04
Connect M6e 5g Firmware HIGH 8.2
CVE-2026-50205

System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware MEDIUM 6.8
CVE-2026-50206

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Mitigation only
Fix from $1,600 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49191

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware HIGH 8.8
CVE-2026-49194

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive she…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 8.6
CVE-2026-49202

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allo…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 8.3
CVE-2026-49203

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or delet…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 7.5
CVE-2026-49193

Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware MEDIUM 6.5
CVE-2026-49204

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Mitigation only
Fix from $1,600 2026-06-04
Connect M6e 5g Firmware MEDIUM 5.4
CVE-2026-49192

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device d…

Mitigation only
Fix from $1,600 2026-06-04
Connect M6e 5g Firmware HIGH 8.8
CVE-2026-49190

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installa…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49188

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execu…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware HIGH 7.8
CVE-2026-49189

Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware HIGH 7.5
CVE-2026-49187

The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.

No fix yet
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49185

The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49186

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +…

Mitigation only
Fix from $2,300 2026-06-04
Wave 7 Firmware CRITICAL 9.8
CVE-2026-49201

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify…

Mitigation only
Fix from $2,300 2026-05-29
Predator Connect W6x Firmware CRITICAL 9.8
CVE-2026-49199

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

Mitigation only
Fix from $2,300 2026-05-29
Wave 7 Firmware CRITICAL 9.8
CVE-2026-49200

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentia…

Mitigation only
Fix from $2,300 2026-05-29
Predator Connect W6x Firmware CRITICAL 9.8
CVE-2026-49197

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fai…

Mitigation only
Fix from $2,300 2026-05-29
Predator Connect W6x Firmware HIGH 8.8
CVE-2026-49195

Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execut…

Mitigation only
Fix from $1,950 2026-05-29