CVE-2026-49200
critical · 10The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
10
CVSS
0.5%
EPSS (exploit prob.)
43rd
EPSS percentile
2026-05-29
Published
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-532
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| acer | wave_7_firmware | <= t7c_gbl_1.01.000055 |
| acer | wave_7 | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-49200