Acer Wave 7 Mesh Routers — Max-Severity Unauthenticated Zero-Days CVE-2026-49200 (Cleartext Credential Disclosure) & CVE-2026-49201 (Hardcoded AES Key Backdoor)

Acer Wave 7 Mesh Routers (TL-2026-0674), also tracked as Acer Wave 7 Router Zero-Days, is a critical-severity software vulnerability scored CVSS 10, first published 2026-06-03. It has no confirmed attribution, affects Acer Acer Wave 7 Wi-Fi 7 Mesh Router, references 2 CVEs (CVE-2026-49200, CVE-2026-49201), maps to 9 MITRE ATT&CK techniques (T1005, T1021, T1078), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-0674

Threat ID
TL-2026-0674
Also known as
Acer Wave 7 Router Zero-Days, Acer Wave 7 acer_cgi.log / upload.cgi Flaws
Severity
CRITICAL
CVSS
10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-06-03
Last reviewed
2026-06-03
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
consumer, small business, soho, remote workforce
Target regions
Global
Detection rules
9
Indicators of compromise
12

Acer disclosed two CVSS 4.0 10.0 zero-day vulnerabilities in its Wave 7 Wi-Fi 7 mesh routers (firmware T7c_GBL_1.01.000055 and earlier), reported by researcher Gergo Pap. CVE-2026-49200 (CWE-532) exposes the acer_cgi.log file without authentication via the web interface, leaking cleartext web and Telnet credentials. CVE-2026-49201 (CWE-798) is a hardcoded AES key in the upload.cgi backup-processing binary that lets an unauthenticated remote attacker decrypt, modify, and re-encrypt system backups to inject a persistent firmware-level backdoor. No patch exists as of disclosure; Acer targets a firmware fix by end of June 2026.

How Acer Wave 7 Mesh Routers works

Acer confirmed two maximum-severity (CVSS 4.0 base 10.0) zero-day vulnerabilities affecting Wave 7 Wi-Fi 7 mesh routers running firmware build T7c_GBL_1.01.000055 or earlier. Both flaws are network-reachable, require no authentication and no user interaction, and were privately reported to Acer by independent security researcher Gergo Pap. Acer published the advisory and assigned both CVEs as the issuing CNA on 2026-05-29; public reporting followed on 2026-06-03. No security patch was available at disclosure, leaving an open exposure window until Acer's targeted firmware fix at the end of June 2026.

CVE-2026-49200 — Broken Access Control / Sensitive Information in Log File (CWE-532). The device firmware writes an operational log, acer_cgi.log, that is retrievable through the router web interface with no authentication. The file contains cleartext login credentials for both the web management interface and the Telnet service. An unauthenticated remote attacker who can reach the management interface simply requests the log file and harvests valid administrator credentials, yielding full unauthorized system access. Because the credentials are valid accounts, subsequent logins to the web UI and Telnet are indistinguishable from legitimate administration absent network-layer monitoring.

CVE-2026-49201 — Use of Hard-coded Cryptographic Key (CWE-798). The upload.cgi binary responsible for processing device configuration/system backups embeds a static, hardcoded AES encryption key. Because the same key protects every device's backups, an unauthenticated attacker can decrypt an intercepted or attacker-generated backup blob, modify its contents (e.g., inject startup scripts, enable services, or alter credentials), re-encrypt it with the known key so the integrity/authenticity check passes, and have the router accept it. This converts the backup-restore path into a persistent, firmware-level backdoor injection primitive that survives reboots and, potentially, factory-reset workflows that re-apply a saved configuration.

Exploit chain. The two flaws compose into a complete unauthenticated compromise: (1) Initial Access — retrieve acer_cgi.log over HTTP to obtain cleartext admin/Telnet credentials (CVE-2026-49200), or directly weaponize the backup path; (2) Credential Access — parse cleartext web and Telnet credentials from the log; (3) Persistence — craft a malicious backup, encrypt it with the hardcoded AES key (CVE-2026-49201), and restore it via upload.cgi to implant a durable backdoor; (4) Lateral Movement / C2 — reuse harvested credentials over Telnet or the web UI, and pivot from the compromised edge device into the internal network the router fronts. A perimeter mesh router is a high-value foothold: it terminates the WAN, sees all internal traffic, and is trusted by downstream clients.

Exploitation status. As of 2026-06-03 there is no confirmed in-the-wild exploitation and no public packaged proof-of-concept; however, the exploitation mechanics for CVE-2026-49200 are fully described in the vendor advisory and reduce to an unauthenticated file fetch, making practical exploitation trivial once the management interface is reachable. There are no network/C2 indicators of compromise associated with this disclosure (no observed adversary infrastructure), so no BeaconBeagle C2 correlation applies; the actionable IOCs are device-local artifacts (acer_cgi.log, upload.cgi) and behavioral signatures (unauthenticated access to the log path, anomalous backup uploads).

Mitigation. Until firmware is released, disable remote (Internet-side) management of the router and, where the firmware permits, restrict remote administration to a trusted IP allowlist. Treat any Wave 7 already exposed to the Internet as potentially compromised: rotate web and Telnet credentials, disable Telnet, and audit the running configuration/backups for unauthorized changes once patched. Apply the Acer firmware update immediately on release via System Management > Firmware Update.

MITRE ATT&CK techniques used in TL-2026-0674

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services

Defense Evasion

T1078 Valid Accounts

Initial Access

T1190 Exploit Public-Facing Application

Credential Access

T1552 Unsecured Credentials

Impact

T1565 Data Manipulation

Reconnaissance

T1595 Active Scanning

defense-impairment

T1600 Weaken Encryption; T1601 Modify System Image

Affected products and versions in Acer Wave 7 Mesh Routers

  • Acer — Acer Wave 7 Wi-Fi 7 Mesh Router
    Vulnerable versions: Firmware T7c_GBL_1.01.000055 and earlier
    Fixed in: Pending — Acer firmware update targeted end of June 2026

Remediation for Acer Wave 7 Mesh Routers

Patches

  • No patch available as of 2026-06-03; Acer targets a firmware fix by end of June 2026. Apply the update on release via System Management > Firmware Update.

Immediate actions

  • Disable remote (Internet-side) management on the Acer Wave 7 router web interface
  • Where firmware permits, restrict remote administration to a trusted IP allowlist
  • Disable the Telnet service if not required
  • Rotate web and Telnet credentials after applying the patch (harvested cleartext credentials must be considered compromised)

Workarounds

  • Disable remote management
  • Restrict Internet remote access to trusted IP addresses
  • Disable Telnet

Longer-term hardening

  • Place SOHO/edge routers behind network monitoring that can flag unauthenticated access to management endpoints
  • Audit router running configuration and stored backups for unauthorized changes after patching
  • Adopt vendor-firmware update SLAs and asset inventory for edge networking devices

CVEs associated with Acer Wave 7 Mesh Routers

CVE-2026-49200, CVE-2026-49201

Weaknesses (CWE) in Acer Wave 7 Mesh Routers

CWE-532, CWE-798

Timeline of Acer Wave 7 Mesh Routers

  • Acer published security advisory KB 19673 describing the broken access control and hardcoded AES key flaws in Wave 7 mesh routers, crediting researcher Gergo Pap.
  • Acer (as issuing CNA) assigned and published CVE-2026-49200 (CWE-532) and CVE-2026-49201 (CWE-798), each rated CVSS 4.0 base 10.0.
  • No firmware patch available; both vulnerabilities remain unpatched, widening the exposure window for unauthenticated network attackers.
  • Acer recommended interim mitigations: disable remote management and, where supported, restrict Internet remote access to trusted IP addresses.
  • BleepingComputer publicly reported the two max-severity Wave 7 zero-days affecting firmware T7c_GBL_1.01.000055 and earlier.
  • Acer targets release of a corrective firmware update by the end of June 2026 (estimated date).

Sources cited for Acer Wave 7 Mesh Routers

Threats related to Acer Wave 7 Mesh Routers

Detection coverage for TL-2026-0674

As of 2026-06-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0674 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats