Acer Wave 7 Router Zero-Days Expose User Credentials

TL;DR. Acer confirmed two maximum-severity zero-day vulnerabilities in its Wave 7 mesh routers, allowing unauthorized credential access and backdoor injection. - The flaws permit unauthenticated remote users to view plaintext login details from log files. - A hardcoded cryptographic key enables attackers to modify system backups for persistent backdoor access. - Acer is developing firmware updates to resolve these security issues by the end of June 2026.

Sources

Back to QLANKR News