Impact
Fixed AES‑128‑CBC keys inside the Acer Connect OTA application allow attackers to forge authorization credentials for arbitrary IMEI numbers, enabling them to list catalog items and extract protected binaries from pre‑signed cloud links. The vulnerability permits unauthorized access to firmware binaries and device impersonation, exposing the router to firmware theft and potential future compromise.
Affected Systems
Acer Connect M6E 5G Portable WiFi Router models are affected. No specific software or firmware versions are listed in the advisory, so any units running the described OTA application are potentially vulnerable.
Risk and Exploitability
The CVSS base score of 6.9 categorizes the flaw as a moderate‑severity risk. Because the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, the likelihood of widespread exploitation remains uncertain. The attack vector is not explicitly stated in the description, but it is inferred that an attacker can interact with the OTA service over the network to supply forged credentials, indicating a network‑based threat that requires no local interaction with the device.
OpenCVE Enrichment