Impact
The vulnerability causes the device to record SMTP authentication passwords and employee corporate identification data in plain text within system logs. This exposes confidential credentials and personal data, allowing an attacker who obtains the logs to steal login credentials and potentially gain unauthorized access to corporate resources. The weakness corresponds to CWE-532, Log File Manipulation.
Affected Systems
Acer Connect M6E 5G Portable WiFi Router. No specific firmware version information is provided.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS score is not available, and the issue is not listed in CISA KEV. The likely attack vector is local or remote access to device logs, but the exact vector is not specified; thus the risk depends on how the logs are stored and accessed.
OpenCVE Enrichment