CRITICAL
Acer Wave 7 router: Hardcoded Cryptographic Key
Published May 29, 2026
10.0
CRITICALCVSS 4.0
EPSS 0.31%
Description
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.
Affected products
-
- Version T7c_GBL_1.01.000055StatusaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Acer | Wave 7 router | unaffected |
|
AND
- ≤ t7c_gbl_1.01.000055
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://community.acer.com/en/kb/articles/19673 Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33271 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://community.acer.com/en/kb/articles/19673 | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33271 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Acer
Published May 29, 2026
Updated May 29, 2026
Reserved May 28, 2026
Link CVE-2026-49201
CISA Vulnrichment
Updated May 29, 2026
ENISA EUVD
EUVD-2026-33271 Assigner Acer
Published May 29, 2026
Updated May 29, 2026
Exploited since n/a
Link EUVD-2026-33271