Back to search
CVE-2026-49201
Published: May 29, 2026
Modified: May 29, 2026
PUBLISHED
Description
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.
| Vendor | Product | Versions |
|---|---|---|
Acer | Wave 7 router | affected T7c_GBL_1.01.000055 - <= * |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now