Beveiligingsadvies

CVE-2026-49201

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-29 08:57:54
Laatst bijgewerkt 2026-05-29 10:53:32
Toegewezen door Acer
CVSS-score 10.0
Status PUBLISHED

Beschrijving

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.