CVE-2026-49203

HIGH WAF: Low
CVSS 8.3 Published: 2026-06-04
CWE-287

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
acerconnect_m6e_5g_firmwareup to m6e_ai_1.00.000019

References

Back to CVE Database