CVE-2026-12495: Stack-Based Buffer Overflow in the Mercusys MB115-4G
Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the httpgdprdecrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mercusys MB115-4G web interfaceto a version that resolves this vulnerability.Fixed in V1_1.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12495?
The severity of CVE-2026-12495 is rated as critical with a CVSS score of 9.2.
How do I fix CVE-2026-12495?
To fix CVE-2026-12495, it is recommended to update the firmware of the Mercusys MB115-4G device to the latest version provided by the manufacturer.
What kind of attack does CVE-2026-12495 facilitate?
CVE-2026-12495 facilitates a denial-of-service (DoS) attack due to a stack buffer overflow.
Which device is affected by CVE-2026-12495?
CVE-2026-12495 affects the Mercusys MB115-4G device.
How can an attacker exploit CVE-2026-12495?
An attacker can exploit CVE-2026-12495 by sending a specially crafted request to the /cgi/login endpoint.