Description
Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overflow vulnerability in the administrative web interface allows an authenticated attacker with administrative privileges to trigger a system crash by sending a specially crafted request. The vulnerability results in denial of service through control flow manipulation to an arbitrary instruction address.
Published: 2026-07-09
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack buffer overflow exists in the administrative web interface of the Mercusys MW302R router. The overflow allows an authenticated user with administrative privileges to send a specially crafted request that manipulates the control flow to an arbitrary instruction address, causing the device to crash. This flaw is a classic buffer overflow (CWE-121) and results in a denial of service, preventing legitimate administrative access until the router is rebooted or patched.

Affected Systems

The vulnerability affects Mercusys MW302R routers running firmware version 1.1.4.10 Build 231023, specifically the EU variant. No other vendors or products are listed as impacted.

Risk and Exploitability

Because the flaw requires administrative authentication, the attack vector is likely local or internal, possibly from a compromised user. The CVSS score of 5.7 indicates medium severity, while the EPSS score of <1% and lack of inclusion in CISA's KEV catalog suggest that exploitation is currently unlikely to be widely observed. Nevertheless, an attacker who can authenticate to the administrative interface can bring the router down, disrupting network connectivity until reboot or patching occurs.

Generated by OpenCVE AI on July 29, 2026 at 12:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to a version that resolves the buffer overflow.
  • If a firmware update is not yet available, apply network-level restrictions to limit external access to the administrative interface, such as firewall rules or IP whitelisting.
  • Enable logging and set alerts for anomalous requests against the administration interface to detect attempted exploitation.

Generated by OpenCVE AI on July 29, 2026 at 12:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Stack Buffer Overflow in Mercusys MW302R Router Administration Interface Causing Denial of Service

Sun, 26 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Stack Buffer Overflow in Mercusys MW302R Router Administration Interface Causing Denial of Service

Fri, 24 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Admin Web Interface Causes Denial of Service on Mercusys MW302R

Tue, 21 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Admin Web Interface Causes Denial of Service on Mercusys MW302R

Thu, 16 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Admin Web Interface of Mercusys MW302R Router Causes System Crash

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Admin Web Interface of Mercusys MW302R Router Causes System Crash

Tue, 14 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Mercusys MW302R Router Enables Denial of Service

Mon, 13 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Mercusys MW302R Router Enables Denial of Service

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Stack Buffer Overflow in Mercusys MW302R Administrative Interface Enables Denial of Service

Sat, 11 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Stack Buffer Overflow in Mercusys MW302R Administrative Interface Enables Denial of Service

Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Mercusys
Mercusys mw302r
Vendors & Products Mercusys
Mercusys mw302r

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overflow vulnerability in the administrative web interface allows an authenticated attacker with administrative privileges to trigger a system crash by sending a specially crafted request. The vulnerability results in denial of service through control flow manipulation to an arbitrary instruction address.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-10T15:31:02.333Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31267

cve-icon Vulnrichment

Updated: 2026-07-10T15:30:54.388Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T13:00:16Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow