Acer Wave 7 Router Zero-Days Expose User Credentials
TL;DR. Acer confirmed two maximum-severity zero-day vulnerabilities in its Wave 7 mesh routers, allowing unauthorized credential access and backdoor injection. - The flaws permit unauthenticated remote users to view plaintext login details from log files. - A hardcoded cryptographic key enables attackers to modify system backups for persistent backdoor access. - Acer is developing firmware updates to resolve these security issues by the end of June 2026.
- Acer Wave 7 routers have two critical zero-day vulnerabilities.
- One flaw allows unauthenticated remote access to plaintext credentials in log archives.
- The second vulnerability uses a hardcoded cryptographic key for backdoor injection.
- Acer plans to release firmware patches by June 2026 to address these issues.
Sources
- Acer working to patch max severity zero-days in Wave 7 routers — bleepingcomputer.com