Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-12495
Stack-Based Buffer Overflow in the Mercusys MB115-4G
CVE-2026-31267
Buffer Overflow in Mercusys MW302R Administrative Web Interface
CVE-2026-36602
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInfo action. An unauthenticated attacker on the adjacent network can obtain a raw MIPS KSEG0 kernel pointer, revealing kernel memory layout and aiding further exploitation.
CVE-2026-36604
DNS Rebinding Vulnerability in Mercusys AC12G Router Permits Remote Management Access
CVE-2026-36607
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to the login endpoint (code=7). An attacker on the adjacent network can attempt unlimited passwords without triggering account lockout.
