CVE-2026-49186

Acer · Connect M6E 5G Portable WiFi Router

The local MQTT broker on the Acer Connect M6E 5G router fails to enforce ACLs, allowing unauthorized clients to enumerate devices and publish rogue commands.

Executive summary

A critical access control vulnerability in the Acer Connect M6E 5G router’s MQTT broker allows unauthorized clients to manipulate network devices and intercept data.

Vulnerability

The local MQTT broker lacks topic-level Access Control Lists (ACLs). This allows any client to use wildcard characters to subscribe to sensitive topics, enumerate hidden network devices, or publish unauthorized control commands.

Business impact

The lack of access control exposes the internal network architecture and allows for rogue control of connected IoT/network devices. With a CVSS score of 9.8, this flaw poses a significant risk to the integrity and availability of the local network environment.

Remediation

Immediate Action: Update to the latest firmware version to ensure proper MQTT broker configuration and ACL enforcement are implemented.

Proactive Monitoring: Monitor MQTT traffic for unexpected subscription patterns or unauthorized publish requests.

Compensating Controls: Isolate the router from untrusted network segments and restrict access to the MQTT broker port (typically 1883) to authorized internal clients only.

Exploitation status

Public Exploit Available: False

Analyst recommendation

The vulnerability significantly undermines the security of the local network. Organizations should prioritize updating the device firmware to enforce necessary access controls on the MQTT broker.