CVE-2026-49195: Predator Connect W6x: unauthenticated Debug Service
Unauthenticated Debug Service. The /sbin/mtkdut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Predator Connect W6x (firmware)to a version that resolves this vulnerability.Fixed in W6x_GBL_2.00.000008 - Compensating control
Restrict network access to the debug service by preventing LAN-based access to TCP port 9000 where /sbin/mtk_dut is exposed; allow only trusted management sources or block the port entirely until patched.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49195?
The severity of CVE-2026-49195 is rated as high with a score of 8.7.
How do I fix CVE-2026-49195?
To fix CVE-2026-49195, update to firmware version W6x_GBL_2.00.000008.
What type of vulnerability is CVE-2026-49195?
CVE-2026-49195 is an unauthenticated debug service vulnerability.
Who is affected by CVE-2026-49195?
CVE-2026-49195 affects devices running the Acer Predator Connect W6x.
What can an attacker do with CVE-2026-49195?
An attacker can execute arbitrary UCC commands on the exposed debug service without authentication.