Acer has warned about two maximum-severity vulnerabilities affecting its Wave 7 routers running firmware version T7c_GBL_1.01.000055 or earlier. Both flaws received a critical severity score of 10.0, which is basically the vulnerability scoring system’s way of screaming into a pillow. Acer says it is working on firmware updates and expects fixes to be available by the end of June 2026. 

What Was Found 

The first issue is a broken access control flaw where the acer_cgi.log file can be accessed without authentication through the router’s web interface. According to Acer’s advisory, this log file contains cleartext login credentials for web and Telnet access, which could allow unauthorized access to the device. ([Acer Community][1])

The second issue involves a hardcoded AES encryption key in the upload.cgi binary used for processing device backups. Acer says this could allow an attacker to decrypt, modify, and re-encrypt backups, making persistent backdoor injection possible. That is not just a bug. That is the router politely holding the door open and offering tea. 

Why This Matters 

Routers are not ordinary devices. They sit at the edge of the network and control traffic flowing between users, devices, and the internet. If a router is compromised, attackers may be able to intercept traffic, alter DNS behavior, create persistence, pivot deeper into the network, or use the device as part of a larger botnet.

This is especially serious because home and small-office routers are often poorly monitored. Users may update laptops and phones regularly, but routers are frequently forgotten after installation. They sit quietly in a corner blinking like they are innocent, while running outdated firmware from the age of bad decisions.

What Users Should Do 

Acer Wave 7 users should check their firmware version and apply the upcoming firmware update as soon as Acer releases it. Acer recommends updating through the router administration console by accessing [http://192.168.76.1](http://192.168.76.1) or [http://acerconnect.com](http://acerconnect.com), going to System Management, and selecting Firmware Update. 

Until a patch is available, users should reduce exposure wherever possible. Remote administration from the internet should be disabled unless absolutely required. Telnet should not be exposed. Default passwords should be changed, admin access should be limited to trusted local devices, and unnecessary services should be turned off.

Organizations using such routers in branch offices or small locations should inventory affected devices, confirm firmware versions, restrict management access, and monitor for suspicious configuration changes, unknown admin access, unexpected DNS modifications, and unusual outbound traffic.

Final Comment 

The Acer Wave 7 router advisory is another reminder that network devices must be treated as critical infrastructure, not as “set it and forget it” appliances. A router with exposed credentials or weak firmware protection can become an easy entry point into the entire network.

The lesson is simple: keep router firmware updated, disable unnecessary management access, remove insecure services, and monitor edge devices with the same seriousness given to servers and endpoints. Attackers understand the value of routers very well. Defenders should stop treating them like plastic boxes with blinking lights and start treating them like the security boundary they actually are.


Acer is working to address two maximum-severity zero-day vulnerabilities affecting its Wave 7 mesh routers. [...]

Source: Acer working to patch max severity zero-days in Wave 7 routers via Bleeping Computer — published 03 Jun 2026.