Description
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory to unauthenticated adjacent network attackers.
Published: 2026-06-03
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the handling of UPnP SOAP requests on the router. When a POST request is received on port 1900 without a SOAPAction header, the device returns 128 bytes of uninitialized memory, leaking internal data that could help an attacker gather information about the device or surrounding network. The primary impact is the disclosure of sensitive information; there is no evidence of code execution or privilege escalation. The weakness involves uninitialized reads and unauthorized access to local information (CWE-200).

Affected Systems

Mercusys AC12G (EU) V1 running firmware version AC12G(EU)_V1_200909 is the only product explicitly listed as affected. No other products or firmware revisions appear in the advisory; users of newer firmware should verify release notes for potential fixes.

Risk and Exploitability

Based on the description, the attack vector is likely local‑network delivery of malformed UPnP POST requests. An attacker can trigger the vulnerability by sending unauthenticated POST traffic on port 1900 without a SOAPAction header, without needing any credentials. Because the flaw is confined to the UPnP port on a local LAN segment, the risk is limited to devices within the same network. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. However, the disclosed memory contents might aid reconnaissance or credential‑guessing, giving the flaw some value in a focused local‑network attack scenario.

Generated by OpenCVE AI on June 3, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest version that removes the uninitialized buffer issue.
  • Disable UPnP or block POST traffic on port 1900 that lacks a SOAPAction header, using the router’s firewall settings.
  • Restrict local network access to the router by placing it on a separate VLAN or by blocking port 1900 from non‑trusted sub‑nets.

Generated by OpenCVE AI on June 3, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Mercusys
Mercusys ac12g
Vendors & Products Mercusys
Mercusys ac12g

Wed, 03 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Buffer Leakage via UPnP POST Without SOAPAction

Wed, 03 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Buffer Leakage via UPnP POST Without SOAPAction

Wed, 03 Jun 2026 17:45:00 +0000

Type Values Removed Values Added
Description Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory to unauthenticated adjacent network attackers.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-03T19:35:56.761Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36611

cve-icon Vulnrichment

Updated: 2026-06-03T19:35:49.406Z

cve-icon NVD

Status : Deferred

Published: 2026-06-03T18:16:22.357

Modified: 2026-06-04T15:41:35.193

Link: CVE-2026-36611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T10:12:24Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor