← Back to browse · API

CVE-2026-49201

Severity
CRITICAL
CVSS
10.0
EPSS
0.00262
Risk score
40.09
CISA KEV
No
PoC
No
Published
2026-05-29
Modified
2026-05-29
First seen
2026-08-05
Aliases
EUVD-2026-33271, GHSA-5XRR-7Q3M-RH98
Products
Acer:Wave 7 router T7c_GBL_1.01.000055 ≤*, acer:wave_7, acer:wave_7_firmware
Sources
nvd CVE-2026-49201
euvd EUVD-2026-33271

Description

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.

References