Acer Preparing Fixes for Critical Zero-Day Flaws in Wave 7 Routers
Acer is preparing firmware updates for two critical zero-day vulnerabilities affecting Wave 7 routers. The flaws can expose plaintext login credentials and allow attackers to tamper with router backups for persistent access, so users should disable remote management until patches are released and install the firmware update as soon as it becomes available.
Acer has confirmed that it is preparing firmware updates to address two maximum-severity zero-day vulnerabilities affecting its Wave 7 mesh routers.
According to the company’s security advisory, the vulnerabilities were reported by security researcher Gergo Pap and impact Acer Wave 7 routers running firmware version T7c_GBL_1.01.000055 or earlier.
The first vulnerability, tracked as CVE-2026-49200, is a broken access control flaw that could allow unauthenticated remote attackers to access plaintext credentials stored in device log archives.
Acer said the issue involves the acer_cgi.log file, which is accessible through the router’s web interface without authentication. The file may contain cleartext login credentials for both the web administration panel and Telnet, potentially allowing attackers to gain unauthorized access to affected devices.
The second vulnerability, tracked as CVE-2026-49201, involves a hardcoded cryptographic key in the router’s backup-handling component. Acer said the upload.cgi binary, which processes device backups, contains a hardcoded AES encryption key. An attacker could use this key to decrypt, modify, and re-encrypt system backups, potentially enabling persistent backdoor access to the router.
Acer has not yet released patches for the two vulnerabilities, but the company said fixes are planned for deployment by the end of June 2026 through upcoming firmware updates.
Until patches are available, Acer recommends that customers reduce exposure by disabling remote management where possible. If remote management must remain enabled, users should restrict internet-based access to trusted IP addresses only, if supported by the device firmware.
Once the firmware updates are released, Acer strongly recommends that all Wave 7 users install them immediately. Users can update their router by connecting to the device over Wi-Fi or Ethernet, opening the router administration console at http://192.168.76.1 or http://acerconnect.com, logging in with administrator credentials, and navigating to System Management > Firmware Update > Check for Updates.
Because the vulnerabilities can expose administrator credentials and enable persistent unauthorized access, affected routers should be treated as high-risk until patched. Users should also consider changing router administrator passwords after applying the firmware update, especially if remote management was previously enabled.
Comments
0 public comments
No comments yet
Be the first to add a comment to this article.
Add a comment
Please sign in to comment on this article.
Sign In