Acer working to patch max severity zero-days in Wave 7 routers
… The first zero-day, a broken access control vulnerability tracked as CVE-2026-49200 , can allow unauthenticated attackers to remotely access plaintext credentials stored in log archives. "The acer cgi.log file in the device firmware is accessible without authentication via the web interface. …