Skip to content
COOEY

EXPOSURES › CVE-2026-49200

CVE-2026-49200

CRITICAL
DETAIL
SourceNVD · cve Published2026-05-29 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-49200 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.