Acer Devices Authentication Bypass Vulnerability Allowing Access to Cleartext Login Credentials
Vulnerability
An authentication bypass vulnerability has been identified in the web interface of certain Acer devices. The issue arises because the acer_cgi.log file is accessible without authentication, and this file contains cleartext login credentials for both web and Telnet access. As a result, unauthorized users can gain system access by exploiting this vulnerability.
Impact
Exploitation of this vulnerability allows unauthorized access to the system using the exposed cleartext login credentials for web and Telnet interfaces.
Added: May 29, 2026, 9:18 AM
Updated: May 29, 2026, 9:18 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
0.0relevance
9.7threat
0.0urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
