CVE-2026-49190

HIGH WAF: High
CVSS 8.8 Published: 2026-06-04
CWE-78

The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
acerconnect_m6e_5g_firmwareup to m6e_ai_1.00.000019

References

Back to CVE Database