Acer Devices Unauthenticated Debug Service Vulnerability in UCC Command Execution

Vulnerability

A vulnerability exists in certain Acer devices where the /sbin/mtk_dut binary is accessible on TCP port 9000 without authentication. This exposure allows any attacker on the local network to execute arbitrary UCC commands.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands, potentially allowing for further exploitation of the device or network.

Added: May 29, 2026, 9:23 AM
Updated: May 29, 2026, 9:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.9
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.