CVE-2026-50214

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

critical 9.8 CVSS 3.1
Published: Jun 4, 2026
Modified: Jun 8, 2026
Vendor: Acer
Product: Connect M6E 5G Firmware

Description

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

References

Related CVEs