MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listenhttplan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listenhttplan parameter to uhttpd.json is manually fixed.
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'srcdportstart', 'srcdportend', and 'destport' parameters.
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLess/../../etc/passwd URI.
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.