CVE-2026-49200

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
References
Link Resource
https://community.acer.com/en/kb/articles/19673 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:acer:wave_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:acer:wave_7:-:*:*:*:*:*:*:*

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) El archivo acer_cgi.log en el firmware del dispositivo es accesible sin autenticación a través de la interfaz web. Este archivo contiene credenciales de inicio de sesión en texto claro (para web y Telnet), lo que lleva a un acceso no autorizado al sistema.

08 Jun 2026, 12:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://community.acer.com/en/kb/articles/19673 - () https://community.acer.com/en/kb/articles/19673 - Vendor Advisory
CPE cpe:2.3:o:acer:wave_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:acer:wave_7:-:*:*:*:*:*:*:*
First Time Acer wave 7
Acer wave 7 Firmware
Acer

29 May 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 09:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-49200

Mitre link : CVE-2026-49200

CVE.ORG link : CVE-2026-49200


JSON object : View

Products Affected

acer

  • wave_7_firmware
  • wave_7
CWE
CWE-532

Insertion of Sensitive Information into Log File