Cyber Security News

Acer Confirms Patch in Progress for Wave 7 Router 0-Day Flaw

Acer has confirmed that it is actively developing a firmware patch to address critical zero-day vulnerabilities affecting its Wave 7 routers, following responsible disclosure by an independent security researcher.

According to an official advisory published on June 2, 2026, the vulnerabilities impact Acer Wave 7 devices running firmware version T7c_GBL_1.01.000055 or earlier.

The flaws expose sensitive system components and could allow unauthenticated attackers to gain full control over affected devices.

Overview of the Vulnerabilities

Broken Access Control Exposes Credentials

A critical broken access control vulnerability affects the Acer Wave 7 router, allowing the acer_cgi.log file to be accessed without authentication via the web interface.

This log file contains sensitive information, including plaintext administrative and Telnet credentials, which could allow remote attackers to obtain valid login credentials and gain unauthorized access to the device.

The flaw is classified under CWE-532 and carries a CVSS score of 10.0, indicating maximum severity due to its ease of exploitation and impact on system security.

Hardcoded AES Key Enables Persistent Backdoor Injection

Another critical flaw exists in the upload.cgi binary, which contains a hardcoded AES encryption key used for processing backup files. Attackers can leverage this key to decrypt, modify, and re-encrypt configuration backups, enabling persistent compromise through malicious configuration injection.

This vulnerability falls under CWE-798 and also carries a CVSS score of 10.0. Successful exploitation can result in long-term unauthorized control over the router and potential lateral movement within connected networks.

Both vulnerabilities are remotely exploitable without requiring authentication or user interaction, significantly increasing the risk of exploitation. Threat actors could leverage these issues to gain full administrative access, extract sensitive data, establish persistence, and potentially pivot into connected internal networks.

Such attacks could lead to surveillance, data theft, or broader network compromise, particularly in home and small-office environments where these routers are widely deployed.

Acer stated that a security firmware update is currently in development and is expected to be released by the end of June 2026. Users are strongly advised to apply the update as soon as it becomes available to mitigate potential risks.

In the meantime, users should take precautionary measures, such as restricting access to the router management interface, turning off unnecessary services, and monitoring device activity for suspicious behavior.

To update the firmware once released, users should access the router administration panel via http://192.168.76.1 or http://acerconnect.com, log in with administrator credentials, navigate to the firmware update section under system management, and check for updates.

Acer warns users not to interrupt the update process, as doing so may corrupt the device firmware and render the router unusable.

Acer credited security researcher Gergo Pap for responsibly disclosing the vulnerabilities. The incident underscores persistent security challenges in embedded devices, particularly insecure logging practices and hardcoded cryptographic keys, which continue to pose significant risks in modern network environments.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure

Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model…

3 hours ago

700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution

OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after…

3 hours ago

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page…

4 hours ago

Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover

A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin,…

5 hours ago

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform.…

5 hours ago

Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days

A cyber incident reportedly forced a small UK power generation facility offline for about four…

5 hours ago