CVE-2026-49199

CRITICAL WAF: High
CVSS 9.8 Published: 2026-05-29
CWE-77

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
acerpredator_connect_w6x_firmwareup to w6x_gbl_2.00.000005

References

Back to CVE Database