PatchSiren cyber security CVE debrief
CVE-2026-50207 Acer CVE debrief
A local privilege escalation vulnerability in Acer Connect M6E 5G firmware allows authenticated local attackers to send unverified AT commands through the Binder interface. The flaw enables reading baseband files or disabling cellular connectivity. The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), though the description indicates an AT command injection/bypass issue rather than a traditional path traversal. The CVSS 4.0 vector indicates local attack vector with low attack complexity, low privileges required, and high impacts to confidentiality, integrity, and availability of the vulnerable component.
- Vendor
- Acer
- Product
- Connect M6E 5G firmware
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-04
- Original CVE updated
- 2026-06-04
- Advisory published
- 2026-06-04
- Advisory updated
- 2026-06-04
Who should care
Organizations deploying Acer Connect M6E 5G mobile hotspots or routers; telecommunications administrators managing cellular edge devices; security teams monitoring IoT/telecom infrastructure for baseband compromise or connectivity disruption risks
Technical summary
The Binder IPC boundary in Acer Connect M6E 5G firmware fails to validate or restrict AT commands passed through from local applications. This allows any local application with basic access to issue pass-through AT commands directly to the baseband processor. Consequences include unauthorized reading of baseband file systems and the ability to disable cellular connectivity. The vulnerability requires local access and low privileges, with no user interaction needed. The attack complexity is low and the vulnerability has been analyzed by NVD with a HIGH severity rating.
Defensive priority
HIGH
Recommended defensive actions
- Apply firmware update M6E_AI_1.00.000020 or later when available from Acer
- Restrict physical and logical access to affected devices to trusted administrators only
- Monitor for unexpected cellular connectivity changes or baseband configuration modifications
- Review device logs for anomalous AT command execution patterns
- Contact Acer support for patch availability if running firmware version M6E_AI_1.00.000019 or earlier
Evidence notes
NVD analyzed status as of 2026-06-04. Vendor advisory published at community.acer.com. CPE criteria confirm affected product as Acer Connect M6E 5G firmware versions up to and including M6E_AI_1.00.000019.
Official resources
-
CVE-2026-50207 CVE record
CVE.org
-
CVE-2026-50207 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
8fc372e3-d9c5-46e4-9410-38469745c639 - Mitigation, Vendor Advisory
2026-06-04