CVE-2026-49201

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.

critical 9.8 CVSS 3.1
Published: May 29, 2026
Modified: Jun 8, 2026
Vendor: Acer
Product: Wave 7 Firmware

Description

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.

References

Related CVEs