Acer Wave 7 Mesh Routers — Max-Severity Unauthenticated Zero-Days CVE-2026-49200 (Cleartext Credential Disclosure) & CVE-2026-49201 (Hardcoded AES Key Backdoor) — Threadlinqs Intelligence
As of 2026-06-03, Acer Wave 7 Mesh Routers — Max-Severity Unauthenticated Zero-Days CVE-2026-49200 (Cleartext Credential Disclosure) & CVE-2026-49201 (Hardcoded AES Key Backdoor) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 12 indicators of compromise.
Threat ID: TL-2026-0674 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Acer disclosed two CVSS 4.0 10.0 zero-day vulnerabilities in its Wave 7 Wi-Fi 7 mesh routers (firmware T7c_GBL_1.01.000055 and earlier), reported by researcher Gergo Pap. CVE-2026-49200 (CWE-532)
Acer confirmed two maximum-severity (CVSS 4.0 base 10.0) zero-day vulnerabilities affecting Wave 7 Wi-Fi 7 mesh routers running firmware build T7c_GBL_1.01.000055 or earlier. Both flaws are network-reachable, require no authentication and no user interaction, and were privately reported to Acer by independent security researcher Gergo Pap. Acer published the advisory and assigned both CVEs as the issuing CNA on 2026-05-29; public reporting followed on 2026-06-03. No security patch was available at disclosure, leaving an open exposure window until Acer's targeted firmware fix at the end of June 2026.
CVE-2026-49200 — Broken Access Control / Sensitive Information in Log File (CWE-532). The device firmware writes an operational log, acer_cgi.log, that is retrievable through the router web interface with no authentication. The file contains cleartext login credentials for both the web management interface and the Telnet service. An unauthenticated remote attacker who can reach the management interface simply requests the log file and harvests valid administrator credentials, yielding full unauthorized system access. Because the credentials are valid accounts, subsequent logins to the web UI and Telnet are indistinguishable from legitimate administration absent network-layer monitoring.
CVE-2026-49201 — Use of Hard-coded Cryptographic Key (CWE-798). The upload.cgi binary responsible for processing device configuration/system backups embeds a static, hardcoded AES encryption key. Because the same key protects every device's backups, an unauthenticated attacker can decrypt an intercepted or attacker-generated backup blob, modify its contents (e.g., inject startup scripts, enable services, or alter credentials), re-encrypt it with the known key so the integrity/authenticity check passes, and have the router accept it. This converts the backup-restore path into a persistent, firmware-level backdoor injection primitive that survives reboots and, potentially, factory-reset workflows that re-apply a saved configuration.
Exploit chain. The two flaws compose into a complete unauthenticated compromise: (1) Initial Access — retrieve acer_cgi.log over HTTP to obtain cleartext admin/Telnet credentials (CVE-2026-49200), or directly weaponize the backup path; (2) Credential Access — parse cleartext web and Telnet credentials from the log; (3) Persistence — craft a malicious backup, encrypt it with the hardcoded AES key (CVE-2026-49201), and restore it via upload.cgi to implant a durable backdoor; (4) Lateral Movement / C2 — reuse harvested credentials over Telnet or the web UI, and pivot from the compromised edge device into the internal network the router fronts. A perimeter mesh router is a high-value foothold: it terminates the WAN, sees all internal traffic, and is trusted by downstream clients.
Exploitation status. As of 2026-06-03 there is no confirmed in-the-wild exploitation and no public packaged proof-of-concept; however, the exploitation mechanics for CVE-2026-49200 are fully described in the vendor advisory and reduce to an unauthenticated file fetch, making practical exploitation trivial once the management interface is reachable. There are no network/C2 indicators of compromise associated with this disclosure (no observed adversary infrastructure), so no BeaconBeagle C2 correlation applies; the actionable IOCs are device-local artifacts (acer_cgi.log, upload.cgi) and behavioral signatures (unauthenticated access to the log path, anomalous backup uploads).
Mitigation. Until firmware is released, disable remote (Internet-side) management of the router and, where the firmware permits, restrict remote administration to a trusted IP allowlist. Treat any Wave 7 already exposed to the Internet as potentially compromised: rotate web and Telnet credentials, disable Telnet, and audit the running configuration/backups for unauthorized changes once patched. Apply the Acer firmware update immediately on release via System Management > Firmw
Weaknesses (CWE)
CWE-532, CWE-798
Target sectors: consumer, small business, soho, remote workforce
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 12 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-49200, CVE-2026-49201, T1595, T1190, T1552, T1552, T1600, T1078, T1601, T1021, T1005, T1565