CVE-2026-36615: Infoleak
Published Jun 3, 2026
·Updated
Mercusys AC12G (EU) V1 with firmware AC12G(EU)V1200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer contents to unauthenticated attackers on the adjacent network.
Affected Software
1 affected component
MERCUSYS AC12G (EU) V1=AC12G(EU)_V1_200909
Event History
Jun 3, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-36615?
CVE-2026-36615 has a medium severity rating of 4.3 based on the CVSS v3.1 scoring system.
2
How does CVE-2026-36615 affect the Mercusys AC12G (EU) V1?
CVE-2026-36615 allows unauthenticated attackers on an adjacent network to access internal buffer contents via an undocumented endpoint.
3
What is the risk associated with exploiting CVE-2026-36615?
The risk associated with CVE-2026-36615 is an information leak, which can expose sensitive internal data to potential attackers.
4
How can I mitigate the vulnerability CVE-2026-36615?
To mitigate CVE-2026-36615, users should restrict access to the device network and regularly update the firmware to the latest version.
5
When was CVE-2026-36615 published?
CVE-2026-36615 was published on June 3, 2026.