CVE-2026-49200

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
References
Link Resource
https://community.acer.com/en/kb/articles/19673 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:acer:wave_7_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:acer:wave_7:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-29 09:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-49200

Mitre link : CVE-2026-49200

CVE.ORG link : CVE-2026-49200


JSON object : View

Products Affected

acer

  • wave_7_firmware
  • wave_7
CWE
CWE-532

Insertion of Sensitive Information into Log File