Vulnerability Details CVE-2026-49200
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-49200
-
-
cpe:2.3:o:acer:wave_7_firmware:t7c_gbl_1.01.000055