Executive brief
The Acer Wave 7 router contains a security flaw where sensitive system logs are accessible to anyone on the network without a password. These logs contain the administrator's login credentials for both the web management interface and remote terminal access (Telnet) in plain text. An attacker can use this information to take full control of the router, potentially monitoring network traffic, changing security settings, or disrupting internet connectivity.
Technical details
A broken access control vulnerability exists in the Acer Wave 7 router firmware (version T7c_GBL_1.01.000055 and earlier) due to improper protection of log files. The file 'acer_cgi.log' is exposed via the web server and can be retrieved by unauthenticated remote attackers. This log file contains sensitive information, specifically cleartext credentials for the web administration interface and Telnet service. Successful exploitation allows an attacker to gain full administrative access to the device. Acer has announced that a fix is planned for deployment by the end of June 2026.
Affected products
- Acer Wave 7 Router T7c_GBL_1.01.000055 and earlier
Timeline
- 2026-05-29: advisory: Initial disclosure by Acer and NVD publication
- 2026-06-30: patched: Target date for firmware update deployment