Wave 7

Vendor:

First CVE: May 29, 2026 · Active for under a year

2
Total CVEs
More Total CVEs than 49% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
9.8
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Wave 7 over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2026
55 days ago
Most Recent CVE
May 29, 2026
56 days ago

CVE Severity & Scoring

Wave 72 CVEs
All CVEs352,231 CVEs
Critical
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (2 CVEs).

2 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups
May 29, 20269.841NONO
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leadin
May 29, 20269.841NONO

Exploit Exposure

Signals from CVEs in this product scope (2 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (2 CVEs).

Media Mentions

Signals from CVEs in this product scope (2 CVEs).

Top CWEs

Versions

No cataloged versions.