CVE-2026-49200
10.0
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 8fc372e3-d9c5-46e4-9410-38469745c639 (Secondary)
Description
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
Affected (1)
Products: Acer: Wave 7 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to t7c_gbl_1.01.000055 |
| Running on/with | Platform Versions |
|---|---|
Acer Wave 7 | All versions |
References (1)
Source: 8fc372e3-d9c5-46e4-9410-38469745c639
Vendor Advisory
Timeline
No history available yet.