Scworld Acer Addresses Critical Zero-Day Vulnerabilities in Wave 7 Routers
Article Content
- •Two critical zero-day vulnerabilities (CVE-2026-49200 and CVE-2026-49201) affect Acer's Wave 7 routers.
- •The vulnerabilities allow unauthorized access to plaintext credentials and persistent backdoor access.
- •Acer plans to release patches by the end of June 2026; users should restrict remote access in the meantime.
Acer is working to patch two critical zero-day vulnerabilities affecting its Wave 7 mesh routers. The vulnerabilities, reported by researcher Gergo Pap, impact firmware version T7c_GBL_1.01.000055 and earlier. CVE-2026-49200 allows unauthenticated attackers to access plaintext credentials stored in log archives, while CVE-2026-49201 involves a hardcoded cryptographic key that enables persistent backdoor access. Acer plans to release firmware updates to address these issues by the end of June 2026. Until patches are available, users are advised to disable remote management or restrict access to trusted IP addresses. The vulnerabilities pose a significant risk due to their potential for remote exploitation without authentication.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Acer and CVE-2026-49200 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…