CVE-2026-49191

CRITICAL WAF: Low
CVSS 9.8 Published: 2026-06-04
CWE-287

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
acerconnect_m6e_5g_firmwareup to m6e_ai_1.00.000019

References

Back to CVE Database