CVE-2026-49200
Acer Wave 7 router, wave 7 firmware, wave 7
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
- CVSS
- 10
- EPSS
- 0.52% 41.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.29