Acer Wave 7 Mesh Routers — Max-Severity Unauthenticated Zero-Days CVE-2026-49200 (Cleartext Credential Disclosure) & CVE-2026-49201 (Hardcoded AES Key Backdoor)
Acer Wave 7 Mesh Routers (TL-2026-0674), also tracked as Acer Wave 7 Router Zero-Days, is a critical-severity software vulnerability scored CVSS 10, first published 2026-06-03. It has no confirmed attribution, affects Acer Acer Wave 7 Wi-Fi 7 Mesh Router, references 2 CVEs (CVE-2026-49200, CVE-2026-49201), maps to 9 MITRE ATT&CK techniques (T1005, T1021, T1078), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-0674
- Threat ID
- TL-2026-0674
- Also known as
- Acer Wave 7 Router Zero-Days, Acer Wave 7 acer_cgi.log / upload.cgi Flaws
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-06-03
- Last reviewed
- 2026-06-03
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- consumer, small business, soho, remote workforce
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
Acer disclosed two CVSS 4.0 10.0 zero-day vulnerabilities in its Wave 7 Wi-Fi 7 mesh routers (firmware T7c_GBL_1.01.000055 and earlier), reported by researcher Gergo Pap. CVE-2026-49200 (CWE-532) exposes the acer_cgi.log file without authentication via the web interface, leaking cleartext web and Telnet credentials. CVE-2026-49201 (CWE-798) is a hardcoded AES key in the upload.cgi backup-processing binary that lets an unauthenticated remote attacker decrypt, modify, and re-encrypt system backups to inject a persistent firmware-level backdoor. No patch exists as of disclosure; Acer targets a firmware fix by end of June 2026.
How Acer Wave 7 Mesh Routers works
Acer confirmed two maximum-severity (CVSS 4.0 base 10.0) zero-day vulnerabilities affecting Wave 7 Wi-Fi 7 mesh routers running firmware build T7c_GBL_1.01.000055 or earlier. Both flaws are network-reachable, require no authentication and no user interaction, and were privately reported to Acer by independent security researcher Gergo Pap. Acer published the advisory and assigned both CVEs as the issuing CNA on 2026-05-29; public reporting followed on 2026-06-03. No security patch was available at disclosure, leaving an open exposure window until Acer's targeted firmware fix at the end of June 2026.
CVE-2026-49200 — Broken Access Control / Sensitive Information in Log File (CWE-532). The device firmware writes an operational log, acer_cgi.log, that is retrievable through the router web interface with no authentication. The file contains cleartext login credentials for both the web management interface and the Telnet service. An unauthenticated remote attacker who can reach the management interface simply requests the log file and harvests valid administrator credentials, yielding full unauthorized system access. Because the credentials are valid accounts, subsequent logins to the web UI and Telnet are indistinguishable from legitimate administration absent network-layer monitoring.
CVE-2026-49201 — Use of Hard-coded Cryptographic Key (CWE-798). The upload.cgi binary responsible for processing device configuration/system backups embeds a static, hardcoded AES encryption key. Because the same key protects every device's backups, an unauthenticated attacker can decrypt an intercepted or attacker-generated backup blob, modify its contents (e.g., inject startup scripts, enable services, or alter credentials), re-encrypt it with the known key so the integrity/authenticity check passes, and have the router accept it. This converts the backup-restore path into a persistent, firmware-level backdoor injection primitive that survives reboots and, potentially, factory-reset workflows that re-apply a saved configuration.
Exploit chain. The two flaws compose into a complete unauthenticated compromise: (1) Initial Access — retrieve acer_cgi.log over HTTP to obtain cleartext admin/Telnet credentials (CVE-2026-49200), or directly weaponize the backup path; (2) Credential Access — parse cleartext web and Telnet credentials from the log; (3) Persistence — craft a malicious backup, encrypt it with the hardcoded AES key (CVE-2026-49201), and restore it via upload.cgi to implant a durable backdoor; (4) Lateral Movement / C2 — reuse harvested credentials over Telnet or the web UI, and pivot from the compromised edge device into the internal network the router fronts. A perimeter mesh router is a high-value foothold: it terminates the WAN, sees all internal traffic, and is trusted by downstream clients.
Exploitation status. As of 2026-06-03 there is no confirmed in-the-wild exploitation and no public packaged proof-of-concept; however, the exploitation mechanics for CVE-2026-49200 are fully described in the vendor advisory and reduce to an unauthenticated file fetch, making practical exploitation trivial once the management interface is reachable. There are no network/C2 indicators of compromise associated with this disclosure (no observed adversary infrastructure), so no BeaconBeagle C2 correlation applies; the actionable IOCs are device-local artifacts (acer_cgi.log, upload.cgi) and behavioral signatures (unauthenticated access to the log path, anomalous backup uploads).
Mitigation. Until firmware is released, disable remote (Internet-side) management of the router and, where the firmware permits, restrict remote administration to a trusted IP allowlist. Treat any Wave 7 already exposed to the Internet as potentially compromised: rotate web and Telnet credentials, disable Telnet, and audit the running configuration/backups for unauthorized changes once patched. Apply the Acer firmware update immediately on release via System Management > Firmware Update.
MITRE ATT&CK techniques used in TL-2026-0674
Collection
Lateral Movement
Defense Evasion
Initial Access
T1190 Exploit Public-Facing Application
Credential Access
Impact
Reconnaissance
defense-impairment
Affected products and versions in Acer Wave 7 Mesh Routers
- Acer — Acer Wave 7 Wi-Fi 7 Mesh Router
Vulnerable versions: Firmware T7c_GBL_1.01.000055 and earlier
Fixed in: Pending — Acer firmware update targeted end of June 2026
Remediation for Acer Wave 7 Mesh Routers
Patches
- No patch available as of 2026-06-03; Acer targets a firmware fix by end of June 2026. Apply the update on release via System Management > Firmware Update.
Immediate actions
- Disable remote (Internet-side) management on the Acer Wave 7 router web interface
- Where firmware permits, restrict remote administration to a trusted IP allowlist
- Disable the Telnet service if not required
- Rotate web and Telnet credentials after applying the patch (harvested cleartext credentials must be considered compromised)
Workarounds
- Disable remote management
- Restrict Internet remote access to trusted IP addresses
- Disable Telnet
Longer-term hardening
- Place SOHO/edge routers behind network monitoring that can flag unauthenticated access to management endpoints
- Audit router running configuration and stored backups for unauthorized changes after patching
- Adopt vendor-firmware update SLAs and asset inventory for edge networking devices
CVEs associated with Acer Wave 7 Mesh Routers
CVE-2026-49200, CVE-2026-49201
Weaknesses (CWE) in Acer Wave 7 Mesh Routers
CWE-532, CWE-798
Timeline of Acer Wave 7 Mesh Routers
- Acer published security advisory KB 19673 describing the broken access control and hardcoded AES key flaws in Wave 7 mesh routers, crediting researcher Gergo Pap.
- Acer (as issuing CNA) assigned and published CVE-2026-49200 (CWE-532) and CVE-2026-49201 (CWE-798), each rated CVSS 4.0 base 10.0.
- No firmware patch available; both vulnerabilities remain unpatched, widening the exposure window for unauthenticated network attackers.
- Acer recommended interim mitigations: disable remote management and, where supported, restrict Internet remote access to trusted IP addresses.
- BleepingComputer publicly reported the two max-severity Wave 7 zero-days affecting firmware T7c_GBL_1.01.000055 and earlier.
- Acer targets release of a corrective firmware update by the end of June 2026 (estimated date).
Sources cited for Acer Wave 7 Mesh Routers
- Acer working to patch max severity zero-days in Wave 7 routers
- Acer Security Advisory: Upcoming Firmware Update for Acer Wave 7 Router (KB 19673)
- CVE-2026-49200 — Vulnerability-Lookup (CIRCL)
- CVE-2026-49201 — Vulnerability-Lookup (CIRCL)
- NVD — CVE-2026-49200
- NVD — CVE-2026-49201
- Acer Wave 7 Wi-Fi 7 Mesh Router — Product Support
Threats related to Acer Wave 7 Mesh Routers
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164 SharePoint) Among Record 570+ Fixes
- Linux Kernel act_pedit COW Out-of-Bounds Write Enables Local Privilege Escalation to Root (CVE-2026-46331)
- CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure (CVE-2025-68686) and Arista VeloCloud Orchestrator OS Command Injection (CVE-2026-16812)
- Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly Disclosed
- Cisco Catalyst SD-WAN Manager CVE-2026-20245 — Actively Exploited 0-Day: Authenticated File-Upload Command Injection to Root
- Multiple WolfSSL Critical Vulnerabilities: Certificate Bypass, RCE, and Post-Quantum Weakening
Detection coverage for TL-2026-0674
As of 2026-06-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0674 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.