Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-50212 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-06-04 6.5 Medium
Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.
CVE-2026-50213 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-06-04 7.5 High
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.