FAIL › dossier
acer
VENDORDossier not yet built — the RAG curator builds one for players with ≥2 failure events. The failure history and sentiment below are live.
FAILURE HISTORY · 13
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-10-19 | CVE-2022-41415 | critical | Acer Altos W2000h-W570h F4 R01.03.0018 was discovered to contain a stack overflow in the RevserveMem component. This vulnerability allows attackers to cause a Denial of Service (DoS) via injecting crafted shellcode into the NVRAM variable. |
| 2026-06-04 | CVE-2026-50225 | critical | CVE-2026-50225: The registration path /v1/account/register provides no bot mitigation mechanisms |
| 2026-06-04 | CVE-2026-49191 | critical | CVE-2026-49191: The production build of the M3WebServer hard-codes its backend API keys, which c |
| 2026-06-04 | CVE-2026-50208 | critical | CVE-2026-50208: High-risk TrustAllCerts routines disable standard TLS certificate validation. Co |
| 2026-06-04 | CVE-2026-50211 | critical | CVE-2026-50211: Leftover engineering diagnostics and factory-level diagnostic software remain ex |
| 2026-06-04 | CVE-2026-50214 | critical | CVE-2026-50214: The /v1/Plan service relies entirely on a shared global API token for full admin |
| 2026-06-04 | CVE-2026-49186 | critical | CVE-2026-49186: The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). |
| 2026-06-04 | CVE-2026-49188 | critical | CVE-2026-49188: The ai_cmd utility executes with full root permissions. It pipes socket inputs d |
| 2026-06-04 | CVE-2026-49185 | critical | CVE-2026-49185: The FieldX MDM adb messaging topic passes unverified payloads directly into Runt |
| 2026-05-29 | CVE-2026-49201 | critical | CVE-2026-49201: The upload.cgi binary, responsible for processing device backups, contains a har |
| 2026-05-29 | CVE-2026-49197 | critical | CVE-2026-49197: Web endpoints intended for the Acer Connect app improperly validate the HTTP Aut |
| 2026-05-29 | CVE-2026-49200 | critical | CVE-2026-49200: The acer_cgi.log file in the device firmware is accessible without authenticatio |
| 2026-05-29 | CVE-2026-49199 | critical | CVE-2026-49199: Crafted MQTT messages can trigger command injection, resulting in root-level cod |