External risk intelligence

Acer Connect M6E 5G Debugging Flaw Bypasses Login for Shell Access

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-49194

The affected product is a 5G router/gateway device. Such devices are commonly deployed at the network edge to provide internet connectivity, making their management interfaces or device services reachable from the public internet in many standard deployment scenarios.

Authentication Bypass

Acer Connect M6e 5g Firmware

m6e_ai_1.00.000019 and earlier

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability found in a specific Acer 5G router firmware. The issue allows an attacker with low privileges to bypass standard login procedures and gain direct access to an interactive shell, potentially leading to unauthorized control over the device. The primary concern is to confirm if this technology is in use within the organization and assess any potential exposure.

  • Bypasses login for direct system access.
  • Affects devices providing internet connectivity.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with low-privilege access could bypass standard device authentication through a debugging routine, directly gaining an interactive shell. This bypass allows the attacker to interact with the system without going through normal security checks, potentially leading to significant compromise.

  • Requires low-privilege access.
  • Debug routine bypasses login.
  • Direct shell access leads to high risk.

Live Threat

Current exploitation, exposure, and threat context

The debugging routine SCREEN_CLICK(5053) on Acer Connect M6E 5G devices can allow a connection to bypass the standard device login prompt, providing direct access to an interactive shell. This could potentially allow an attacker with network access to gain administrative control over the device when supported by the advisory.

  • Device administrative control and system configurations.
  • Bypassing standard login prompts.
  • Complete device compromise is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world remediation requires understanding where this Acer Connect M6E 5G firmware is deployed. Infrastructure or platform teams likely manage these edge devices, while security teams will need to assess exposure. The initial step is to inventory all instances, confirm network reachability and business criticality, and identify the accountable owner for coordinated remediation.

  • Identify asset owners for affected devices.
  • Verify network exposure and business impact.
  • Plan coordinated remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Acer Connect M6E 5G?

It is a 5G router and gateway device designed to provide high-speed internet connectivity. These devices typically serve as the bridge between a local network and the public internet, managing data traffic and device settings through integrated firmware.

How does CVE-2026-49194 bypass security?

This vulnerability is classified as Improper Authentication (CWE-287). It stems from a debugging routine named SCREEN_CLICK(5053) that erroneously permits a connection to ignore the standard password prompt. By triggering this routine, an unauthorized user can bypass the login gate and immediately interact with the device's underlying shell.

Do I need elevated access to trigger this bug?

No. The vulnerability only requires low-privilege network access to reach the affected debugging routine. It is important to note that standard, authorized interactions with the device interface—such as using the web portal for routine configuration while properly logged in—do not trigger this flaw.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal identifies these routers as likely high-risk because they are often deployed at the network edge. If your router is reachable from the public internet for remote management, it has a broader exposure path than a device restricted solely to a local, internal network.

What is the first step to address this?

Begin by auditing your hardware inventory to locate all Acer Connect M6E 5G units in your environment. Once identified, consult your infrastructure team to verify if these devices are exposed to the internet and determine the accountable owner for applying upcoming firmware updates.

References