Impact
The router does not validate the HTTP Host header, allowing DNS rebinding. An attacker can rebind a domain to the router’s internal IP, directing a client such as a web browser to send requests to the management interface from an external origin. The vulnerability directly permits unauthorized access to the administration interface; based on the description, it is inferred that an attacker could alter settings or obtain credentials once they have access to the interface.
Affected Systems
Mercusys AC12G (EU) V1 router running firmware AC12G(EU)_V1_200909
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk level. EPSS information is not available and the flaw is not listed in the CISA KEV catalog, so the probability of a public exploit is unknown. The likely attack vector is an external DNS rebinding attempt, such as a web browser that can resolve a domain to the router’s internal IP. No special privileges beyond network connectivity and the ability to host a rebinding-capable client are required.
OpenCVE Enrichment