Description
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POST requests to undefined paths, exposing server state to unauthenticated adjacent network attackers.
Published: 2026-06-03
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes that the Mercusys AC12G (EU) V1 router returns 128 bytes of uninitialized internal buffer content when it receives an HTTP POST request to an undefined path. This implies that an unauthenticated attacker who can reach the device over the network can obtain a chunk of the router’s internal state through a simple HTTP request, resulting in a privacy leak of potentially sensitive system data. The weakness is a typical information‑disclosure flaw, allowing a visible breach of confidentiality but not directly compromising authentication or control of the system.

Affected Systems

The affected product is the Mercusys AC12G (EU) V1 router running firmware version AC12G(EU)_V1_200909. No other vendors or products are listed.

Risk and Exploitability

The vulnerability can be exploited by an attacker with network visibility to the device, sending a POST request to any undefined URI. Since the flaw does not require authentication and occurs on an HTTP interface, the attack surface exists for anyone on the same subnet or through any forwarded ports. The EPSS score is not available, but the lack of a KEV listing suggests the exploit is not yet actively leveraged. The CVSS score is 4.3, indicating a moderate risk, while the impact is limited to confidential data exposure with no direct code execution or denial‑of‑service. The risk is moderate, and the probability of exploitation is low to moderate, depending on the attacker’s proximity to the device.

Generated by OpenCVE AI on June 3, 2026 at 20:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware upgrade for the Mercusys AC12G (EU) V1 router as outlined in the official advisory
  • Place the router behind a dedicated VLAN or firewall that permits only trusted internal traffic, effectively reducing the attack surface
  • As a temporary workaround, block or filter HTTP POST requests to all undefined paths using a reverse proxy or firewall rule

Generated by OpenCVE AI on June 3, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Mercusys
Mercusys ac12g
Vendors & Products Mercusys
Mercusys ac12g

Wed, 03 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Title Uninitialized Buffer Disclosure via HTTP POST on Undefined Paths in Mercusys AC12G Router

Wed, 03 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Buffer Disclosure via HTTP POST on Undefined Paths in Mercusys AC12G Router
Weaknesses CWE-125
CWE-200
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 17:45:00 +0000

Type Values Removed Values Added
Description Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POST requests to undefined paths, exposing server state to unauthenticated adjacent network attackers.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-03T18:36:37.518Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36613

cve-icon Vulnrichment

Updated: 2026-06-03T18:36:31.620Z

cve-icon NVD

Status : Deferred

Published: 2026-06-03T18:16:22.617

Modified: 2026-06-04T15:41:35.193

Link: CVE-2026-36613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T10:12:21Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor