CVE-2026-50226: Firmware Theft & IMEI Spoofing via Connect-OTA
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50226?
The severity of CVE-2026-50226 is medium with a CVSS score of 6.9.
What are the risks associated with CVE-2026-50226?
CVE-2026-50226 poses risks of firmware theft and IMEI spoofing, allowing attackers to access unauthorized information.
How do I fix CVE-2026-50226?
To fix CVE-2026-50226, update the AcerConnect OTA application to the latest version provided by Acer.
What exploitation techniques are related to CVE-2026-50226?
Exploitation of CVE-2026-50226 can involve forging authorization credentials using fixed AES-128-CBC keys.
Who is affected by CVE-2026-50226?
Users of the Acer AcerConnect OTA application are affected by CVE-2026-50226 due to vulnerabilities in the app.