Acer
100 known vulnerabilities
Top Products
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrar
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems t
The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall l
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled b
Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to re
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint addres
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read base
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identifi
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote prof
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and dire
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware seri
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unau
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for u
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe usin
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows a
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file conta
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorize
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requ
The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary she
Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a we
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes
In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through
The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000
Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers
Frequently Asked Questions
How many CVEs affect Acer?
Acer has 100 CVE records in our database, including 24 critical and 31 high severity vulnerabilities.
What are the most severe Acer vulnerabilities?
Acer has 24 critical severity (CVSS 9.0+) and 31 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Acer vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Acer products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Acer Vulnerabilities
CyberStrike scans your infrastructure for Acer vulnerabilities and provides real-time remediation guidance.
Get Started