CVE-2026-49196
Analyzed Analyzed - Analysis Complete
Wi-Fi MAC Address Command Injection in Device Blocking Feature

Publication date: 2026-05-29

Last updated on: 2026-06-08

Assigner: 8fc372e3-d9c5-46e4-9410-38469745c639

Description
The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary shell commands.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-29
Last Modified
2026-06-08
Generated
2026-06-19
AI Q&A
2026-05-29
EPSS Evaluated
2026-06-18
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
acer predator_connect_w6x_firmware to w6x_gbl_2.00.000005 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

The vulnerability allows an attacker to execute arbitrary shell commands on the affected device, which can lead to unauthorized control, data compromise, disruption of network services, or further exploitation of the device.

Compliance Impact

The provided information does not explicitly mention the impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Executive Summary

This vulnerability occurs because the Wi-Fi device blocking feature does not properly sanitize the MAC address input. As a result, an attacker can inject and execute arbitrary shell commands on the device.

Detection Guidance

This vulnerability involves command injection via unsanitized MAC address input in the router's web admin panel. Detection can focus on monitoring for unusual or unauthorized shell command executions or suspicious input patterns in MAC address fields.

Specific commands are not provided in the available resources. However, general detection methods could include reviewing router logs for abnormal entries, monitoring network traffic for suspicious activity on the router's web interface, and checking for unexpected processes or shell commands executed on the device.

Mitigation Strategies

The immediate mitigation step is to update the Acer Connect W6x router firmware to version W6x_GBL_2.00.000008 or later, which includes a fix for this vulnerability by improving input validation on the MAC address fields in the web admin panel.

Users should perform the firmware update through the router's admin console and avoid restarting or unplugging the router during the update process to ensure a successful upgrade.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart