← Volver al buscador de CVEs

CVE-2026-49200

acer_cgi.log

Descripción

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.

CVSS 9.8EPSS 0.518%Riesgo 1.03
Ver fuente
Publicación
2026-05-29 09:16:18
Versiones afectadas
unknown
Tipo
Firmware
Última modificación
2026-07-21 12:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H