CVE-2021-25811: High severity mercusys mercury x18g firmware vulnerability
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listenhttplan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listenhttplan parameter to uhttpd.json is manually fixed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25811.
What is the title of the vulnerability?
The title of the vulnerability is 'MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter'.
What is the severity of CVE-2021-25811?
The severity of CVE-2021-25811 is high with a severity value of 7.5.
How can the vulnerability be exploited?
The vulnerability can be exploited by sending a crafted value to the POST listen_http_lan parameter, which causes a denial of service on affected devices.
Is there a fix available for CVE-2021-25811?
There is no information available regarding a fix for CVE-2021-25811. It is recommended to follow the official sources for updates and patches.