Acer working to patch max severity zero-days in Wave 7 routers
Acer is fixing two maximum-severity zero-days in Wave 7 mesh routers, including credential exposure and persistent backdoor risk.
Intelligence analysis by GPT-5.4 Mini

Acer says two critical flaws affect Wave 7 mesh routers on firmware T7c_GBL_1.01.000055 or earlier. One exposes plaintext login details in logs; the other uses a hardcoded key that could let attackers alter backups and keep access.
Acer found two big holes in some home internet boxes. One hole can leak secret login names and passwords from a log file, and the other can help a thief sneak in and stay hidden like a burglar keeping a spare key.
Analysis
What Acer disclosed
Acer says it is working on patches for two maximum-severity zero-days in its Wave 7 mesh routers. The flaws were reported by security researcher Gergo Pap and affect devices running firmware version T7c_GBL_1.01.000055 or earlier.
The two issues
The first issue, tracked as CVE-2026-49200, is a broken access control problem. Acer says the acer_cgi.log file can be reached through the web interface without authentication, and that the log contains cleartext login credentials for web and Telnet access. That creates a direct path to unauthorized system access.
The second issue, CVE-2026-49201, involves a hardcoded cryptographic key in upload.cgi, the component that handles device backups. Acer says this lets an attacker decrypt, modify, and re-encrypt backups. In practical terms, that can support persistent backdoor injection, which is worse than a one-time login theft because the attacker may be able to keep coming back.
What users should do
Acer says no patch is available yet, but fixes are planned for deployment by the end of June 2026. Until then, the company advises users to disable remote management or restrict Internet access to trusted IP addresses if the firmware supports that. Once updates arrive, Acer says users should check the router administration console and install the new firmware immediately.
The story is a reminder that consumer and small-office routers can be high-value targets. When authentication data and backup handling both fail, attackers may be able to move from initial access to durable control very quickly.
Key points
- Acer says two maximum-severity zero-days affect Wave 7 mesh routers on firmware T7c_GBL_1.01.000055 or earlier.
- CVE-2026-49200 can expose plaintext web and Telnet credentials through an unauthenticated log file.
- CVE-2026-49201 uses a hardcoded AES key that could let attackers alter backups and inject a persistent backdoor.
- Acer says patches are planned for release by the end of June 2026.
- Until then, Acer recommends disabling remote management or restricting internet access to trusted IP addresses.
Acer says fixes are already in progress and should ship by the end of June 2026. If users install the update quickly and lock down remote management, the exposure window could be short.
Until patches land, affected routers can leak credentials and allow persistent compromise. If remote management stays open to the internet, attackers may have an easier path to take over devices and maintain access.



