Vulnary
← back to the feed
Critical· 10

CVE-2026-49200

CVE-2026-49200 allows attackers to access a device's firmware log file (acer_cgi.log) via the web interface without authentication. This file contains cleartext login credentials, enabling unauthorized access to the system.

publishedMay 29, 2026
last modifiedJul 21, 2026
sourcesNVD
severity · cvss
10
critical · how bad it is
exploitation · epss
<1%
41th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 4, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users of acer wave_7_firmware and acer wave_7 devices

02

Real-world impact

Attackers could steal credentials from the exposed log file and gain unauthorized access to the device via web or Telnet.

03

Why this severity

Critical (CVSS 10.0) - High risk of immediate system compromise due to exposed credentials.

04

What to do about it

no official fix yet
interim mitigations
  • Restrict web interface access to the acer_cgi.log file via server permissions or firewall rules.
  • Remove or encrypt cleartext credentials stored in the log file if possible.
  • Monitor logs for unauthorized access attempts.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

  1. May 29, 2026 · May 29, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 14d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →