Impact
The flaw allows anyone to retrieve internal multimedia session recordings without any authentication. The exposure is compounded by permissive Cross‑Origin Resource Sharing rules that let external sites download these recordings, effectively enabling cross‑site theft of sensitive meeting content.
Affected Systems
Acer’s Connect M6E 5G Portable WiFi Router is affected. No specific firmware version is disclosed, so all current releases that include the exposed endpoints are at risk.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is considered High severity. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, but the lack of authentication and liberal CORS policy make the attack very straightforward for anyone who can reach the router’s internal network. This makes the risk especially acute in environments where the router is exposed to untrusted traffic or where sensitive recordings are stored.
OpenCVE Enrichment