Acer disclosed two critical zero-day vulnerabilities affecting Wave 7 mesh routers running firmware T7c_GBL_1.01.000055 or earlier, both assigned a CVSS score of 10.0. The flaws, reported by researcher Gergo Pap, are tracked as CVE-2026-49200 and CVE-2026-49201. The first allows unauthenticated attackers to access the internal acer_cgi.log file through the web interface and recover plaintext administrative credentials for the web and Telnet services.
The second vulnerability stems from a hardcoded AES key in the upload.cgi backup-processing component, allowing attackers to decrypt, modify, and re-encrypt router backup files to implant persistent backdoors. Acer said emergency firmware updates were still in development and targeted for release by the end of June 2026. Until patches are available, the company urged customers to disable remote management or restrict Internet access to trusted IP addresses only, and to monitor the router management interface for firmware updates and apply them immediately once released.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
At disclosure time, Acer said patches were not yet available and that emergency firmware updates were targeted for release by the end of June 2026. Until then, the company advised customers to monitor for updates and limit or disable remote management access.
Acer acknowledged and disclosed two maximum-severity flaws affecting Wave 7 devices: CVE-2026-49200, which exposes plaintext administrative credentials via acer_cgi.log, and CVE-2026-49201, which uses a hardcoded AES key to enable tampering with backups for persistent backdoor insertion. Both references describe the vulnerabilities as affecting firmware version T7c_GBL_1.01.000055 or earlier.
Security researcher Gergo Pap reported two vulnerabilities in Acer Wave 7 mesh routers running firmware T7c_GBL_1.01.000055 or earlier. The issues were later tracked as CVE-2026-49200 and CVE-2026-49201.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.