Skip to main content

Vendor/product archive

acer / wave_7_firmware CVEs

Beta · best-effort

2 CVEs tagged to acer / wave_7_firmware2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-49201

Published May 29, 2026

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backup…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49200

Published May 29, 2026

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leadi…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1