Acer Wave 7 Router Zero-Day Vulnerabilities (CVE-2026-49200 & CVE-2026-49201)

CVE-2026-49200 CVE-2026-49201 Zero-Day Router Security
Overview
Acer disclosed two maximum-severity zero-day vulnerabilities affecting Acer Wave 7 mesh routers. The flaws could allow attackers to steal credentials, gain unauthorized access, and establish persistent backdoors on vulnerable devices.
Technical Specifications
| Attribute | Details |
|---|---|
| CVE IDs | CVE-2026-49200, CVE-2026-49201 |
| Affected Product | Acer Wave 7 mesh router |
| Affected Firmware | T7c_GBL_1.01.000055 and earlier |
| CVE-2026-49200 | Unauthenticated access to acer_cgi.log exposing plaintext administrator and Telnet credentials |
| CVE-2026-49201 | Hardcoded AES key in backup restoration (upload.cgi) enabling decryption, tampering, and malicious backup upload |
| Attack Requirements | Network reachability to exposed management/log endpoints |
| Authentication Requirement | Not required for initial credential exposure path |
| Exploitation Impact | Credential theft, privileged access, persistent compromise, and network abuse potential |
| CVSS Severity | Reported as maximum severity in vendor/security reporting |
Affected Products
- Acer Wave 7 mesh routers running firmware version T7c_GBL_1.01.000055 or earlier
- Deployments exposing management interfaces or related services to untrusted networks
- Environments with Telnet enabled and weak perimeter controls
Attack Scenario
- The attacker scans the internet for exposed Acer Wave 7 routers.
- The attacker accesses an exposed log file without authentication.
- Administrator and Telnet credentials are extracted from plaintext log data.
- The attacker logs into the router management interface.
- A tampered backup configuration is uploaded using the hardcoded AES key weakness.
- Persistent access is established and DNS settings or traffic handling are modified.
- The compromised router is used for interception, lateral movement, or botnet activity.
Impact
- Full compromise of router configuration and trusted network controls
- Persistent unauthorized changes through malicious backup restoration
- DNS manipulation and policy tampering that alters normal network behavior
- Theft of administrative and Telnet credentials from exposed logs
- Potential interception of internal network traffic through compromised routing infrastructure
- Increased risk of data exposure during attacker-controlled network redirection
- Service instability or disruption due to malicious configuration changes
- Potential outage scenarios from unauthorized firmware/config operations
- Botnet recruitment and malware distribution affecting local and upstream network reliability
Mitigations
Immediate Actions
- Disable remote management access where possible
- Restrict admin access to trusted IP addresses only
- Change all administrator and Telnet passwords immediately
- Disable Telnet services if unnecessary
Short-term Measures
- Avoid exposing router management interfaces directly to the internet
- Apply Acer firmware updates immediately once released
- Harden router access controls and administrative workflows
Monitoring & Detection
- Monitor for unauthorized configuration changes
- Alert on suspicious outbound traffic patterns from router devices
- Audit authentication attempts and anomalous management-plane activity
Long-term Solutions
- Segment critical internal systems from consumer/edge routing infrastructure
- Establish continuous vulnerability management for network edge devices
- Enforce secure configuration baselines and periodic credential rotation for network appliances
Resources
Official and Open-Source Reporting
Last Updated: June 7, 2026