securityonline.info 6/4/2026, 3:51:04 AM · external

Dual CVSS 10.0 Bugs Fixed in Emergency Acer Router Patch

Dual CVSS 10.0 Bugs Fixed in Emergency Acer Router Patch
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical security alert has been issued regarding vulnerabilities in Acer's Connect W6x devices. The advisories highlight urgent firmware updates due to two serious flaws: CVE-2026-49197, which allows authentication bypass through poor HTTP handling, and CVE-2026-49199, a command injection vulnerability affecting the MQTT broker. Both issues have a CVSS severity rating of 10.0, necessitating immediate action from users to patch their devices.

The firmware update also addresses three additional high-severity vulnerabilities. Users are recommended to update to version W6x_GBL_2.00.000008 or later for optimal security.

View full article

Article by CyberSIXT