Description
Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.
Published: 2026-07-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G web interface. An attacker who can send a specially crafted request to the /cgi/login endpoint can corrupt memory, causing the httpd process to crash. Once crashed, the web administration service becomes unavailable, effectively treating the device as offline for management purposes.

Affected Systems

The issue affects all firmware builds of the Mercusys MB115-4G that predate the security update to V1_1.9.0. No other products or later firmware versions are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity for a remote unauthenticated denial-of-service. The EPSS score of < 1% suggests a low likelihood of exploitation. The absence of a KEV listing does not negate risk. The attack vector is inferred to be remote over the network, requiring only that the attacker reach the device’s web interface and send a malicious request; no authentication is needed. Repeated exploitation can render the device's management interface inoperable, leading to service disruption.

Generated by OpenCVE AI on August 3, 2026 at 17:54 UTC.

Remediation

Vendor Solution

The vulnerability has been fixed by the Mercusys team in version V1_1.9.0.


OpenCVE Recommended Actions

  • Apply the latest firmware V1_1.9.0 to the Mercusys MB115-4G.
  • Restrict access to the web administration interface by configuring firewalls or VPNs to allow only trusted internal IP addresses.
  • If the httpd service crashes, reboot the device to restore the administrative interface and monitor logs for additional crash attempts.

Generated by OpenCVE AI on August 3, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Mercusys
Mercusys mb115-4g
Vendors & Products Mercusys
Mercusys mb115-4g

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.
Title Stack-Based Buffer Overflow in the Mercusys MB115-4G
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mercusys Mb115-4g
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-07-28T06:49:36.326Z

Reserved: 2026-06-17T08:53:55.157Z

Link: CVE-2026-12495

cve-icon Vulnrichment

Updated: 2026-07-27T14:40:47.684Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T12:16:41.027

Modified: 2026-07-28T08:17:14.187

Link: CVE-2026-12495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow