Security Advisory

CVE-2026-49201

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-29 08:57:54
Last updated 2026-05-29 10:53:32
Assigner Acer
CVSS score 10.0
State PUBLISHED

Description

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify, and re-encrypt system backups, facilitating persistent backdoor injection.