The local MQTT broker on the Acer Connect M6E 5G router fails to enforce ACLs, allowing unauthorized clients to enumerate devices and publish rogue co...
Description
The local MQTT broker on the Acer Connect M6E 5G router fails to enforce ACLs, allowing unauthorized clients to enumerate devices and publish rogue commands.
AI Analyst Comment
Remediation
Update Unknown Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Acer
PRODUCT: Connect M6E 5G Portable WiFi Router
AFFECTED_VERSIONS: Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019
---END_METADATA---
Description Summary:
The local MQTT broker on the Acer Connect M6E 5G router fails to enforce ACLs, allowing unauthorized clients to enumerate devices and publish rogue commands.
Executive Summary:
A critical access control vulnerability in the Acer Connect M6E 5G router’s MQTT broker allows unauthorized clients to manipulate network devices and intercept data.
Vulnerability Details
CVE-ID: CVE-2026-49186
Affected Software: Acer Connect M6E 5G Portable WiFi Router
Affected Versions: Acer Connect M6E 5G Portable WiFi Router up to M6E_AI_1.00.000019
Vulnerability: The local MQTT broker lacks topic-level Access Control Lists (ACLs). This allows any client to use wildcard characters to subscribe to sensitive topics, enumerate hidden network devices, or publish unauthorized control commands.
Business Impact
The lack of access control exposes the internal network architecture and allows for rogue control of connected IoT/network devices. With a CVSS score of 9.8, this flaw poses a significant risk to the integrity and availability of the local network environment.
Remediation Plan
Immediate Action: Update to the latest firmware version to ensure proper MQTT broker configuration and ACL enforcement are implemented.
Proactive Monitoring: Monitor MQTT traffic for unexpected subscription patterns or unauthorized publish requests.
Compensating Controls: Isolate the router from untrusted network segments and restrict access to the MQTT broker port (typically 1883) to authorized internal clients only.
Exploitation Status
Public Exploit Available: False
Analyst Notes: As of Jun 4, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
The vulnerability significantly undermines the security of the local network. Organizations should prioritize updating the device firmware to enforce necessary access controls on the MQTT broker.