CVE-2026-49199: Predator Connect W6x: RCE via MQTT
Published May 29, 2026
·Updated
Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.
Affected Software
3 affected components
Acer Predator Connect W6x
All of the following
Acer Predator Connect W6x Firmware<=w6x_gbl_2.00.000005
Acer Predator Connect W6x
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Predator Connect W6xto a version that resolves this vulnerability.Fixed in W6x_GBL_2.00.000008
Event History
May 29, 2026
CVE Published
via MITRE·08:38 AM
Data Sourced
via MITRE·08:38 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-49199?
CVE-2026-49199 has a critical severity rating of 10.
2
How do I fix CVE-2026-49199?
CVE-2026-49199 can be fixed by updating to firmware version W6x_GBL_2.00.000008.
3
What type of vulnerability is CVE-2026-49199?
CVE-2026-49199 is classified as a command injection vulnerability.
4
What is the risk associated with CVE-2026-49199?
CVE-2026-49199 has a risk score of 87, indicating a high potential for exploitation.
5
What device is affected by CVE-2026-49199?
CVE-2026-49199 affects the Acer Predator Connect W6x device.