Description
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (unbound 1.22.0), aiding targeted attacks against known vulnerabilities.
Published: 2026-06-03
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The device’s DNS resolver improperly answers version.bind CHAOS TXT queries, revealing the underlying software version (Unbound 1.22.0). This disclosure allows an attacker to determine whether the resolver is running a version with known, exploitable weaknesses, enabling more targeted attacks. The vulnerability is an information‑exposure flaw that exposes details that could be used to craft subsequent attacks or confirm the presence of other security gaps. Based on the description, it is inferred that an attacker may leverage this information to locate and exploit known vulnerabilities in Unbound 1.22.0.

Affected Systems

The affected product is Mercusys AC12G (EU) version 1, running firmware AC12G(EU)_V1_200909. No other affected vendors or versions were identified in the advisory. The vulnerability is specific to this firmware build, where the DNS resolver responds to version.bind CHAOS TXT queries with the Unbound 1.22.0 version string.

Risk and Exploitability

The CVSS score reported is 4.3, indicating moderate severity, and the lack of a patch means the flaw remains exploitable. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting it may not be actively exploited yet. The likely attack vector is remote, as any external DNS query can trigger the disclosure. An attacker could employ the exposed version information to research and exploit known vulnerabilities in Unbound 1.22.0, such as known memory corruption or denial‑of‑service bugs. Because the resolver is exposed to the Internet, the exploitability conditions are straightforward: send a CHAOS TXT query to the device’s DNS service and capture the response.

Generated by OpenCVE AI on June 3, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to a version that removes or sanitizes the CHAOS TXT response, or otherwise disables the version.bind query response.
  • If a firmware upgrade is not immediately available, configure a firewall or router to block external DNS queries to the device, limiting the resolver to internal or trusted networks only.
  • As a temporary measure, tune the Unbound configuration on the device to ignore CHAOS queries or to return a generic response, thereby preventing version disclosure.

Generated by OpenCVE AI on June 3, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Mercusys
Mercusys ac12g
Vendors & Products Mercusys
Mercusys ac12g

Wed, 03 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Title DNS Resolver Version Disclosure via CHAOS TXT Queries

Wed, 03 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Title DNS Resolver Version Disclosure via CHAOS TXT Queries
Weaknesses CWE-200

Wed, 03 Jun 2026 17:45:00 +0000

Type Values Removed Values Added
Description Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (unbound 1.22.0), aiding targeted attacks against known vulnerabilities.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-03T19:41:11.651Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36618

cve-icon Vulnrichment

Updated: 2026-06-03T19:41:03.309Z

cve-icon NVD

Status : Deferred

Published: 2026-06-03T18:16:23.020

Modified: 2026-06-04T15:41:35.193

Link: CVE-2026-36618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T10:12:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor