Acer working to patch max severity zero-days in Wave 7 routers
Acer has confirmed the existence of two critical zero-day vulnerabilities in its Wave 7 mesh routers, reported by security researcher Gergo Pap. These flaws, CVE-2026-49200 and CVE-2026-49201, allow unauthorized access to sensitive credentials and enable persistent backdoors. Acer is working to release patches by the end of June 2026, urging users to update their firmware immediately to mitigate the risk.
Acer is facing a significant security issue due to the discovery of two maximum-severity zero-days within its Wave 7 mesh routers. The vulnerabilities, detailed in a recent security advisory, were identified by Gergo Pap and pose a serious risk to user data and system integrity. Specifically, CVE-2026-49200 allows attackers to access plaintext credentials stored in router log files, while CVE-2026-49201 enables persistent backdoor access through a hardcoded AES encryption key within the router's backup processing binary. This situation highlights the importance of proactive security measures and timely patching of vulnerable devices.