logo

Acer working to patch max severity zero-days in Wave 7 routers

ID: d6dd7182-595c-5de0-abbb-d9a1fa217536

STIX ID: report--d6dd7182-595c-5de0-abbb-d9a1fa217536

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Sergiu Gatlan

...
...

Acer disclosed two maximum-severity zero-day flaws in Wave 7 routers (firmware T7c_GBL_1.01.000055 or earlier): an unauthenticated broken access control (CVE-2026-49200) exposing plaintext login credentials from acer_cgi.log, and a hardcoded AES key in upload.cgi (CVE-2026-49201) that permits attackers to decrypt, modify, and re-encrypt backups to inject a persistent backdoor. No fixes are available yet; Acer targets firmware updates by the end of June 2026 and recommends disabling remote management, restricting remote access to trusted IPs, and applying updates once released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.