CVE-2026-36611: Infoleak
Mercusys AC12G (EU) V1 with firmware AC12G(EU)V1200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory to unauthenticated adjacent network attackers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the device's UPnP/SSDP service in the Mercusys AC12G (EU) administration interface to prevent the device from processing POST requests on port 1900 that may return uninitialized memory.
Mercusys AC12G (EU) UPnP/SSDP service UPnP (SSDP) listening on port 1900 = disabled - Compensating control
Block or restrict access to port 1900 (UPnP/SSDP) to the Mercusys device from untrusted or adjacent networks using network firewall rules, VLANs, or host-based firewalls. Only allow access from trusted management networks if absolutely required.
- Operational
Contact Mercusys support and monitor the vendor website for a firmware update that addresses this issue; apply any vendor-provided firmware patch as soon as it becomes available. Until a fix is applied, isolate affected devices from sensitive networks if possible.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36611?
The severity of CVE-2026-36611 is rated as high with a CVSS score of 7.3.
How does CVE-2026-36611 affect the Mercusys AC12G?
CVE-2026-36611 allows unauthenticated adjacent network attackers to access 128 bytes of uninitialized buffer memory.
What is the exploit vector for CVE-2026-36611?
CVE-2026-36611 can be exploited by sending POST requests without a SOAPAction header on UPnP port 1900.
How can I mitigate CVE-2026-36611?
To mitigate CVE-2026-36611, ensure that your Mercusys AC12G router firmware is updated to the latest version.
Is authentication required to exploit CVE-2026-36611?
No, authentication is not required to exploit CVE-2026-36611 since it targets unauthenticated adjacent network attackers.