CVE-2026-36604: Medium severity MERCUSYS AC12G (EU) V1 vulnerability
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)V1200909 does not validate the HTTP Host header, enabling DNS rebinding attacks. An external attacker can rebind a domain to the router's internal IP address, extending the CORS wildcard vulnerability (Access-Control-Allow-Origin: ) to internet-originated attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mercusys AC12G (EU) V1to a version that resolves this vulnerability.Fixed in AC12G(EU)_V1_200909
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36604?
The severity of CVE-2026-36604 is rated medium with a CVSS score of 6.5.
How do I fix CVE-2026-36604?
To mitigate CVE-2026-36604, update the firmware of the Mercusys AC12G (EU) V1 router to the latest version that addresses the vulnerability.
What types of attacks are possible due to CVE-2026-36604?
CVE-2026-36604 enables DNS rebinding attacks, allowing external attackers to manipulate the router's HTTP Host header.
What products are affected by CVE-2026-36604?
CVE-2026-36604 affects the Mercusys AC12G (EU) V1 router specifically with the firmware AC12G(EU)_V1_200909.
What are the implications of CVE-2026-36604 on users?
Users of the affected Mercusys AC12G router may face risks of unauthorized access and control over their internal network due to DNS rebinding attacks.