CVE-2026-49202

HIGH WAF: Low
CVSS 8.6 Published: 2026-06-04
CWE-287

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
acerconnect_m6e_5g_firmwareup to m6e_ai_1.00.000019

References

Back to CVE Database