CVE-2026-36611: Infoleak

Published Jun 3, 2026
·
Updated

Mercusys AC12G (EU) V1 with firmware AC12G(EU)V1200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory to unauthenticated adjacent network attackers.

Affected Software

1 affected component
MERCUSYS AC12G (EU) V1=AC12G(EU)_V1_200909

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable the device's UPnP/SSDP service in the Mercusys AC12G (EU) administration interface to prevent the device from processing POST requests on port 1900 that may return uninitialized memory.

    Mercusys AC12G (EU) UPnP/SSDP service UPnP (SSDP) listening on port 1900 = disabled
  2. Compensating control

    Block or restrict access to port 1900 (UPnP/SSDP) to the Mercusys device from untrusted or adjacent networks using network firewall rules, VLANs, or host-based firewalls. Only allow access from trusted management networks if absolutely required.

  3. Operational

    Contact Mercusys support and monitor the vendor website for a firmware update that addresses this issue; apply any vendor-provided firmware patch as soon as it becomes available. Until a fix is applied, isolate affected devices from sensitive networks if possible.

Event History

Jun 3, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-36611?

The severity of CVE-2026-36611 is rated as high with a CVSS score of 7.3.

2

How does CVE-2026-36611 affect the Mercusys AC12G?

CVE-2026-36611 allows unauthenticated adjacent network attackers to access 128 bytes of uninitialized buffer memory.

3

What is the exploit vector for CVE-2026-36611?

CVE-2026-36611 can be exploited by sending POST requests without a SOAPAction header on UPnP port 1900.

4

How can I mitigate CVE-2026-36611?

To mitigate CVE-2026-36611, ensure that your Mercusys AC12G router firmware is updated to the latest version.

5

Is authentication required to exploit CVE-2026-36611?

No, authentication is not required to exploit CVE-2026-36611 since it targets unauthenticated adjacent network attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203