Acer has confirmed that it is working on fixes for two maximum-severity zero-day vulnerabilities affecting its Wave 7 mesh routers.

The company said the flaws were reported by security researcher Gergo Pap and impacted Wave 7 routers running firmware version T7c_GBL_1.01.000055 or earlier.

The first vulnerability, tracked as CVE-2026-49200, is a broken access control issue that could allow unauthenticated attackers to remotely access plaintext credentials stored in log archives. Acer explained that the acer_cgi.log file in the device firmware can be accessed through the web interface without authentication. The file contains cleartext login credentials for both the web interface and Telnet, which could lead to unauthorized access to the system.

The second vulnerability, tracked as CVE-2026-49201, is linked to a hardcoded cryptographic key inside the router’s firmware. Acer said the upload.cgi binary, which handles device backups, contains a hardcoded AES encryption key. This could allow a remote attacker with no privileges to decrypt, modify, and re-encrypt system backups, making it possible to inject a persistent backdoor into the router.

Acer has not released security patches for the two flaws yet, but the company said fixes are already in development. According to its advisory, the vulnerabilities are expected to be resolved in upcoming firmware updates, with the target release planned for the end of June 2026.

The company strongly urged Wave 7 users to update their router firmware as soon as the security update becomes available. Users can do this by connecting a computer to the Acer Wave 7 router through Wi-Fi or Ethernet, opening the router administration console at 192.168.76.1 or acerconnect.com, logging in with administrator credentials, going to System Management, selecting Firmware Update, and then choosing Check for Updates.


Buy ExpressVPN with PayPal or Credit Card
READ
U.S. Seizes Over 1,000 Illegal Streaming Sites During FIFA World Cup 2026 Crackdown

Until the patch is available, Acer advised customers to reduce the risk of attacks by disabling remote management. Users should also restrict internet-based remote access to trusted IP addresses only if their firmware supports that option.

Advertisement