Vulnerability Description
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Acer | Connect M6E 5G Firmware | <= m6e_ai_1.00.000019 |
| Acer | Connect M6E 5G | - |
Related Weaknesses (CWE)
References
- https://community.acer.com/en/kb/articles/19707MitigationVendor Advisory
FAQ
What is CVE-2026-49192?
CVE-2026-49192 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
How severe is CVE-2026-49192?
CVE-2026-49192 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-49192?
Check the references section above for vendor advisories and patch information. Affected products include: Acer Connect M6E 5G Firmware, Acer Connect M6E 5G.