Acer Devices Command Injection Vulnerability in MQTT Messages Leading to Root-Level Code Execution

Vulnerability

A command injection vulnerability has been identified in certain Acer devices, allowing crafted MQTT messages to execute code with root privileges on the target device.

Impact

Exploitation of this vulnerability allows for unauthorized command execution with root privileges on the affected device.

Added: May 29, 2026, 9:19 AM
Updated: May 29, 2026, 9:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.