CVE-2026-49200 PUBLISHED

Acer Wave 7 router: Broken Access Control

Assigner: Acer
Reserved: 28.05.2026 Published: 29.05.2026 Updated: 29.05.2026

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor Acer
Product Wave 7 router
Versions Default: unaffected
  • affected from T7c_GBL_1.01.000055 to * (incl.)

Credits

  • Gergo Pap reporter

References

Problem Types

  • CWE-532: Sensitive information inserted into log archives CWE

Impacts

  • CAPEC-37: Retrieve Embedded Sensitive Data