Executive brief
The Mercusys MW302R, a wireless router used for home and small office networking, contains a security flaw in its management interface. An authorized administrator can send a specifically formatted request that causes the device to crash or reboot. This results in a total loss of internet connectivity and network services until the device recovers.
Technical details
A stack-based buffer overflow exists within the administrative web interface of the Mercusys MW302R router. The vulnerability is triggered when the web server processes a specially crafted request, leading to control flow manipulation to an arbitrary instruction address. An attacker must be authenticated with administrative privileges to exploit this flaw. Successful exploitation results in a system crash and subsequent denial of service. The issue is fixed in firmware version MW302R(EU)_V1_1.11.10 Build 260327.
Affected products
- Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 and earlier
Timeline
- 2026-04-09: other: CVE reserved
- 2026-04-29: patched: Vendor patch released
- 2026-05-06: disclosed: Public disclosure request submitted
- 2026-07-09: advisory: NVD publication date