CVE-2026-36603: High severity MERCUSYS AC12G (EU) V1 vulnerability
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)V1200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddPortMapping and GetExternalIPAddress. UPnP is enabled by default through the admin interface, allowing any unauthenticated LAN device to create arbitrary port forwarding rules and access WAN traffic statistics.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Log in to the router admin interface and disable UPnP (it is enabled by default) to prevent unauthenticated LAN devices from using UPnP on UDP port 1900 to perform actions like AddPortMapping and GetExternalIPAddress.
Mercusys AC12G (EU) router UPnP = disable
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36603?
CVE-2026-36603 has a high severity rating of 8.1 on the CVSS scale.
What are the risks associated with CVE-2026-36603?
The risks include unauthorized access to UPnP IGD actions, allowing unauthenticated devices on the LAN to potentially manipulate router settings.
How do I fix CVE-2026-36603?
To mitigate CVE-2026-36603, disable UPnP in the router's admin interface.
Which devices are affected by CVE-2026-36603?
CVE-2026-36603 specifically affects the Mercusys AC12G (EU) V1 router.
What exposed services are impacted by CVE-2026-36603?
CVE-2026-36603 exposes multiple UPnP actions, including AddPortMapping and GetExternalIPAddress, without authentication.