Missing Authentication for Critical Function in Acer Connect W6x Router - #VU133368
Published: June 4, 2026
Acer Connect W6x Router
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the device.
The vulnerability exists due to missing authentication in the debugging interface /sbin/mtk_dut on TCP port 9000 when handling LAN-based connections. A remote attacker can connect to the exposed debug service to compromise the device.
The issue is reachable from the local network.