Description
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
Published: 2026-06-04
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the account validation endpoint /v1/User/validate, which returns a full user profile sheet containing private details. The endpoint appears to lack sufficient authentication or access controls; based on the description, it can be queried with predictable identifiers, allowing an attacker to harvest sensitive data from many user accounts. This results in a mass exposure of confidential user information, compromising the confidentiality of all individuals who use the router.

Affected Systems

The only affected system identified is the Acer Connect M6E 5G Portable WiFi Router. No specific firmware versions are listed in the CVE data; users should verify whether their router firmware includes the vulnerability. The Acer community article linked in the references confirms the existence of the issue on this hardware platform. No other vendors or products are mentioned.

Risk and Exploitability

The CVSS score of 8.7 classifies the issue as high severity. EPSS data is not available, so the exploitation probability cannot be quantified. The attack vector is network-based; any user who can send HTTP requests to the router can potentially exploit it. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed live attacks, but the potential for mass data exposure remains a significant risk. Exfiltration occurs simply by requesting the endpoint across a range of account identifiers and capturing the returned data, requiring no special privileges beyond network connectivity to the device.

Generated by OpenCVE AI on June 4, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If an update that addresses the private data disclosure is available, install the latest firmware immediately.
  • Reconfigure the router so that the /v1/User/validate endpoint requires authentication or restrict its access to trusted IP ranges only.
  • If possible, disable or delete any stored user profile information from the router’s local storage to reduce the amount of data that could be exposed.

Generated by OpenCVE AI on June 4, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Acer connect M6e 5g Portable Wifi Router
Vendors & Products Acer connect M6e 5g Portable Wifi Router

Thu, 04 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Acer
Acer connect M6e 5g
Acer connect M6e 5g Firmware
CPEs cpe:2.3:h:acer:connect_m6e_5g:-:*:*:*:*:*:*:*
cpe:2.3:o:acer:connect_m6e_5g_firmware:*:*:*:*:*:*:*:*
Vendors & Products Acer
Acer connect M6e 5g
Acer connect M6e 5g Firmware
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 04 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Jun 2026 08:45:00 +0000

Type Values Removed Values Added
Description The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
Title Bulk User Private Data Harvesting
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Acer Connect M6e 5g Connect M6e 5g Firmware Connect M6e 5g Portable Wifi Router
cve-icon MITRE

Status: PUBLISHED

Assigner: Acer

Published:

Updated: 2026-06-04T12:45:21.552Z

Reserved: 2026-06-04T01:29:10.112Z

Link: CVE-2026-50213

cve-icon Vulnrichment

Updated: 2026-06-04T12:45:14.970Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-04T09:16:29.987

Modified: 2026-06-04T19:10:08.420

Link: CVE-2026-50213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T10:08:42Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials