Vulnerability Intelligence Report
Acer Wave 7 router: Broken Access Control
CVE-2026-49200
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
EPSS Probability:0.52%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-532 ↗CWE-532: Sensitive information inserted into log archives
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Acer | Wave 7 router | T7c_GBL_1.01.000055 <= * (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.518%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Acer Inc. · Vendor · Taiwan |
| Reserved | 2026-05-28T02:47:39 |
| Published | 2026-05-29T08:51:15 |
| Last Updated | 2026-05-29T10:54:23 |
Community Chatter & Buzz