๐Ÿ” CVE Alert

CVE-2026-49201

UNKNOWN 0.0

Acer Wave 7 router: Hardcoded Cryptographic Key

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.

CWE CWE-798
Vendor acer
Product wave 7 router
Published May 29, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for acer wave 7 router

Be the first to know when new unknown vulnerabilities affecting acer wave 7 router are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Acer / Wave 7 router
T7c_GBL_1.01.000055 โ‰ค *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
community.acer.com: https://community.acer.com/en/kb/articles/19673

Credits

๐Ÿ” Gergo Pap