Executive brief
The Acer Wave 7 router contains a hardcoded encryption key within the software responsible for processing device backups. This allows an unauthorized person to decrypt, modify, and re-encrypt system backups. An attacker could use this to inject a permanent 'backdoor' into the device, allowing them to maintain long-term access and control over the network traffic and the device itself.
Technical details
The vulnerability stems from the use of a hardcoded AES cryptographic key within the 'upload.cgi' binary, which is used for processing device backups. An unauthenticated attacker with network access to the router's web interface can leverage this known key to decrypt legitimate backup files, insert malicious code or configuration changes (such as backdoors), and re-encrypt the file for restoration. This results in a complete compromise of device integrity and persistence. The issue is identified as CWE-798 (Use of Hard-coded Credentials) and is scheduled to be patched in a firmware update by the end of June 2026.
Affected products
- Acer Wave 7 Router T7c_GBL_1.01.000055 and earlier
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
- 2026-06-30: patched: Target fix date for firmware update.