Vulnerability Intelligence Report
Predator Connect W6x: Improper Authentication
CVE-2026-49197
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fails.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
EPSS Probability:0.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-287 ↗CWE-287: Improper Authentication
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Acer | Predator Connect W6x | W6x_GBL_2.00.000005 <= * (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.332%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Acer Inc. · Vendor · Taiwan |
| Reserved | 2026-05-28T02:47:39 |
| Published | 2026-05-29T08:24:06 |
| Last Updated | 2026-05-29T11:34:23 |
Community Chatter & Buzz