← Back to browse · API

CVE-2026-49200

Severity
CRITICAL
CVSS
10.0
EPSS
0.00518
Risk score
40.18
CISA KEV
No
PoC
No
Published
2026-05-29
Modified
2026-05-29
First seen
2026-08-05
Aliases
EUVD-2026-33270, GHSA-XF88-3PMX-M4VW
Products
Acer:Wave 7 router T7c_GBL_1.01.000055 ≤*, acer:wave_7, acer:wave_7_firmware
Sources
nvd CVE-2026-49200
euvd EUVD-2026-33270

Description

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.

References