Mercusys

    Dashboard / Vendors

    Products: 10
    Vulnerabilities: 28
    Known Exploited: 0
    2
    Critical Level Threats
    9
    High Level Threats
    16
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-12495

    Stack-Based Buffer Overflow in the Mercusys MB115-4G

    Last Modified: Jul 28, 2026
    Published: Jul 27, 2026

    CVE-2026-31267

    Buffer Overflow in Mercusys MW302R Administrative Web Interface

    Last Modified: Aug 01, 2026
    Published: Jul 09, 2026

    CVE-2026-36602

    Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInfo action. An unauthenticated attacker on the adjacent network can obtain a raw MIPS KSEG0 kernel pointer, revealing kernel memory layout and aiding further exploitation.

    Last Modified: Jun 05, 2026
    Published: Jun 03, 2026

    CVE-2026-36604

    DNS Rebinding Vulnerability in Mercusys AC12G Router Permits Remote Management Access

    Last Modified: Jun 05, 2026
    Published: Jun 03, 2026

    CVE-2026-36607

    Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to the login endpoint (code=7). An attacker on the adjacent network can attempt unlimited passwords without triggering account lockout.

    Last Modified: Jun 05, 2026
    Published: Jun 03, 2026
    Items Per Page
    Mercusys Vulnerabilities & Security CVEs | CVE-DB