Executive brief
A security vulnerability has been identified in the Mercusys MB115-4G wireless router, a device used to provide internet connectivity in homes and small offices. An attacker can exploit this flaw to crash the router's web management interface, preventing administrators from logging in or changing settings. This could disrupt network management operations and require a manual reboot of the device to restore access.
Technical details
A stack-based buffer overflow (CWE-121) exists in the 'http_gdpr_decrypt' function of the Mercusys MB115-4G web interface. The vulnerability is triggered when the '/cgi/login' endpoint receives a specially crafted request, leading to memory corruption. An unauthenticated remote attacker can exploit this to crash the 'httpd' process, resulting in a denial-of-service (DoS) for the web administration service. The issue affects firmware versions 1.7.0 through 1.9.0 and has been addressed in version V1_1.9.0.
Affected products
- Mercusys MB115-4G 1.7.0 through 1.9.0
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched: Fixed in version V1_1.9.0