External risk intelligence

Plan Service Token Vulnerability Allows Arbitrary Network Plan Creation.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-50214

The vulnerability affects a network-facing API service on a consumer network device (5G router). Such devices are commonly deployed at the network edge to provide internet connectivity, and administrative management APIs on these appliances are frequently reachable via the local network or, in some configurations, exposed to the public internet.

Acer Connect M6e 5g Firmware

m6e_ai_1.00.000019 and earlier

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts a network service that manages internet plans, potentially allowing unauthorized administrative control due to a shared, unprotected API token. The main concern is confirming relevance and exposure.

  • Unsecured API token grants broad administrative control.
  • Critical for leaders to understand potential for unauthorized network access.
  • Confirm relevance and potential exposure to your environment.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a request to the `/v1/Plan` service. Because the service uses a shared global API token for administrative tasks and doesn't require specific authentication, an unauthenticated attacker could leverage this to create network access plans without cost, potentially leading to unauthorized resource consumption or disruption.

  • No authentication required to access.
  • Triggered by the `/v1/Plan` service.
  • Allows arbitrary creation of zero-cost plans.

Live Threat

Current exploitation, exposure, and threat context

The `/v1/Plan` service, when exposed, relies on a shared API token that grants full administrative control. This means an attacker could create unlimited, zero-cost network access plans.

  • Network access plans.
  • Shared API token exposure.
  • Uncontrolled network service creation.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability, impacting a network-facing API service, likely falls under the purview of infrastructure or platform teams responsible for network devices and their management interfaces. The immediate practical move is to identify all instances of the affected technology, confirm their exposure and business criticality, and then engage the accountable owner to plan a risk-based remediation.

  • Identify affected devices and owners.
  • Verify network reachability and criticality.
  • Plan and coordinate remediation activities.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Acer Connect M6E 5G firmware affected by CVE-2026-50214?

The Acer Connect M6E 5G is a 5G router designed to provide high-speed internet connectivity. The firmware is the underlying software that manages the router's core networking functions, including the administrative interfaces used to control traffic and subscription-like network access plans. This vulnerability specifically concerns the service responsible for those management operations.

How does CVE-2026-50214 relate to CWE-345?

This vulnerability is classified under CWE-345, which involves the failure to properly verify the authenticity of data. In this case, the system relies on a single, shared global API token to authorize administrative requests. Because the system does not validate that a user has legitimate permissions, it incorrectly trusts any request providing that shared token as if it were a highly privileged administrator.

Does interacting with a different service trigger this vulnerability?

No. The security weakness is localized specifically to the /v1/Plan service. Accessing other router services or management endpoints does not trigger this administrative flaw. The exploit requires direct interaction with the specific Plan endpoint, which performs unauthorized actions because it fails to require unique, individualized authentication for administrative commands.

Why does Halo Surface Signal categorize this as a likely risk?

Halo Surface Signal identifies this as a likely risk because the /v1/Plan service is a network-facing component on a router. Since 5G routers sit at the edge of a network to provide internet access, their management APIs are often reachable from local network segments or, depending on device configuration, exposed directly to the public internet, increasing the potential for unauthorized access.

How should I respond to the CVE-2026-50214 advisory?

Begin by creating an inventory of all Acer Connect M6E 5G devices within your environment to confirm which ones are currently active. Verify their network reachability to determine if they are exposed to untrusted networks. Once you identify the affected units and their owners, coordinate with your infrastructure team to prioritize the necessary updates or security hardening steps required to mitigate the risk.

References