CVE-2026-50224: Unauthenticated IPv6 WAN Management Exposure

Published Jun 4, 2026
·
Updated

The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.

Affected Software

2 affected components
All of the following
Acer Connect M6e 5g Firmware<=m6e_ai_1.00.000019
Acer Connect M6e 5g

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Reconfigure the web administration panel so it does not listen on [::]:8080. Change its bind/listen address to loopback or to a specific internal-only interface to prevent exposure to the IPv6 WAN.

    web administration panel bind_address/listen_address = do not bind to [::]; bind only to internal interfaces or loopback (::1) or a specific internal IPv6 address
  2. Configuration

    If remote IPv6 administration is not required, disable IPv6 WAN management to remove administrative access over the public IPv6 network.

    web administration panel IPv6 WAN management = disabled
  3. Configuration

    Enable and require authentication for the web administration panel and any internal API endpoints so unauthenticated access is not permitted.

    web administration panel authentication = enabled
  4. Compensating control

    Apply firewall rules to block or restrict IPv6 access to TCP port 8080 from the WAN; allow only trusted IP addresses or internal networks to reach the administration/API port.

Event History

Jun 4, 2026
CVE Published
via MITRE·09:26 AM
Data Sourced
via MITRE·09:26 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-50224?

CVE-2026-50224 has a medium severity rating of 6.9 according to the CVSS scoring system.

2

How do I fix CVE-2026-50224?

To fix CVE-2026-50224, restrict access to the web administration panel by implementing a firewall to block external access to port 8080.

3

What are the risks associated with CVE-2026-50224?

The risks include unauthorized access to internal API endpoints due to the web administration panel being exposed to the public IPv6 address space.

4

Which software is affected by CVE-2026-50224?

CVE-2026-50224 affects the Acer Connect M6e 5g Firmware.

5

When was CVE-2026-50224 published?

CVE-2026-50224 was published on June 4, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203