Missing Authentication for Critical Function in Acer Connect W6x Router - #VU133368

 

Missing Authentication for Critical Function in Acer Connect W6x Router - #VU133368

Published: June 4, 2026


Vulnerability identifier: #VU133368
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the device.

The vulnerability exists due to missing authentication in the debugging interface /sbin/mtk_dut on TCP port 9000 when handling LAN-based connections. A remote attacker can connect to the exposed debug service to compromise the device.

The issue is reachable from the local network.


Affected software

Acer Connect W6x Router

Remediation

Install security update from vendor's website.

Acer Connect W6x Router - update to W6x_GBL_2.00.000008

External References

Related Security Bulletins