CVE-2026-36602: Infoleak
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)V1200909 discloses kernel memory layout via the UPnP GetStatusInfo action. An unauthenticated attacker on the adjacent network can obtain a raw MIPS KSEG0 kernel pointer, revealing kernel memory layout and aiding further exploitation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable UPnP on the router or disable the GetStatusInfo action to prevent unauthenticated adjacent-network access to kernel pointers.
Mercusys AC12G (EU) router UPnP UPnP/GetStatusInfo = disabled - Compensating control
Block or filter UPnP/SSDP and related traffic (and restrict access to router management interfaces) at network boundaries or host firewalls so adjacent-network attackers cannot reach the UPnP GetStatusInfo action.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36602?
The severity of CVE-2026-36602 is rated medium with a CVSS score of 4.3.
How do I fix CVE-2026-36602?
To fix CVE-2026-36602, update the Mercusys AC12G (EU) V1 router firmware to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2026-36602?
CVE-2026-36602 is classified as an information leak (CWE-200) due to its disclosure of kernel memory layout.
Who can exploit CVE-2026-36602?
CVE-2026-36602 can be exploited by an unauthenticated attacker on the adjacent network.
What information is disclosed by CVE-2026-36602?
CVE-2026-36602 discloses a raw MIPS KSEG0 kernel pointer, revealing the kernel memory layout.