← Back

Wave 7 Firmware

wave_7_firmware

Vendor: Acer • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Acer
1Wave 7 Firmware
Jul 21, 2026
May 29, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injec...Show more
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.Show less
1Acer
1Wave 7 Firmware
Jul 21, 2026
May 29, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.