---
schema: 1
kind: vulnerability
title: "CVE-2026-49200 / CVE-2026-49201 — Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch"
headline: "CVE-2026-49200 / CVE-2026-49201 — Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch"
summary: "Acer Wave-7 mesh routers — two CVSS 10.0 zero-days, no patch until end-June. An unauthenticated cleartext-credential log (CVE-2026-49200) plus a hardcoded AES key in the backup handler (CVE-2026-49201) chain to full unauth takeover with persistence; Acer's only guidance is interim mitigation (BleepingComputer, 2026-06-03)."
discovered_at: "2026-06-08T05:00:03Z"
event_date: 2026-06-05
run_id: 2026-06-08-1a0ce644
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - zero-day
  - info-disclosure
  - auth-bypass
  - no-patch
regions:
  - europe
  - global
sectors:
  - technology
entities: []
cves:
  - id: CVE-2026-49200
    cvss: "10.0"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: pre-auth
    status:
      - no-patch
      - mitigation-only
  - id: CVE-2026-49201
    cvss: "10.0"
    epss: null
    type: info-disclosure
    vector: zero-click
    auth: pre-auth
    status:
      - no-patch
      - mitigation-only
sources:
  - url: "https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/"
    publisher: BleepingComputer
    role: primary
  - url: "https://www.heise.de/news/Warten-auf-Sicherheitspatch-Zugangsdaten-von-Acer-Wave-7-Router-einsehbar-11318035.html"
    publisher: "heise, 2026-06-05"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Apply Acer's interim mitigations on any Wave-7 mesh routers** ( — no patch exists until end-June. Disable remote administration, restrict the management interface to trusted internal segments, and rotate credentials given the cleartext-log exposure."
migrated_from: briefs/2026-06-08.md
---

Acer warned of two maximum-severity zero-days in Wave-7 mesh routers on firmware `T7c_GBL_1.01.000055` and earlier, with no patch available and a fix targeted only for end-June 2026 ([BleepingComputer, 2026-06-03](https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/); [heise, 2026-06-05](https://www.heise.de/news/Warten-auf-Sicherheitspatch-Zugangsdaten-von-Acer-Wave-7-Router-einsehbar-11318035.html)). **CVE-2026-49200** (broken access control) exposes `acer_cgi.log` — which stores cleartext web-admin and Telnet credentials — to any unauthenticated client that can reach the management interface. **CVE-2026-49201** (hardcoded cryptographic key) is a fixed AES key in the `upload.cgi` backup handler, letting an attacker decrypt, modify and re-encrypt a device backup to inject a persistent backdoor. Together they form an unauthenticated takeover-plus-persistence chain. Inclusion gate: CVSS 10.0 critical-severity, no patch; no confirmed in-the-wild exploitation or public PoC observed yet. Audience relevance is SME / home-office edge rather than core public-sector infrastructure, but the no-patch status makes the interim controls time-sensitive. Mitigations (Acer): disable remote administration, restrict the management interface to trusted internal segments, change default credentials, and watch for unauthorized logins or config changes. Detection concept: alert on unauthenticated HTTP GETs to `/acer_cgi.log` and unexpected backup restore events via `upload.cgi`.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-3300 | Everest Forms Pro (WordPress) | 9.8 | ~30% | No | Yes (mass, since 2026-04-13) | v1.9.13 (2026-03-18) | [Wordfence](https://www.wordfence.com/blog/2026/06/attackers-actively-exploiting-critical-vulnerability-in-everest-forms-pro-plugin/) |
| CVE-2026-49200 | Acer Wave-7 mesh router | 10.0 | n/a | No | No (no PoC seen) | None (≈end-June 2026) | [BleepingComputer](https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/) |
| CVE-2026-49201 | Acer Wave-7 mesh router | 10.0 | n/a | No | No (no PoC seen) | None (≈end-June 2026) | [BleepingComputer](https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/) |
