news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-49200

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.8 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Risk score
78.4
Published
2026-05-29
Status
Analyzed

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.

Weaknesses

CWE-532

Coverage 2

Advisories and references