Junglewise Threat Intelligence

CVE-2026-31267: Mercusys MW302R stack buffer overflow in administrative web interface

CVE-2026-31267 · Severity: info · CVSS 4.9 · Published 2026-07-09

Vendors: Mercusys.

Executive brief

The Mercusys MW302R, a wireless router used for home and small office networking, contains a security flaw in its management interface. An authorized administrator can send a specifically formatted request that causes the device to crash or reboot. This results in a total loss of internet connectivity and network services until the device recovers.

Technical details

A stack-based buffer overflow exists within the administrative web interface of the Mercusys MW302R router. The vulnerability is triggered when the web server processes a specially crafted request, leading to control flow manipulation to an arbitrary instruction address. An attacker must be authenticated with administrative privileges to exploit this flaw. Successful exploitation results in a system crash and subsequent denial of service. The issue is fixed in firmware version MW302R(EU)_V1_1.11.10 Build 260327.

Affected products

  • Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 and earlier

Timeline

  • 2026-04-09: other: CVE reserved
  • 2026-04-29: patched: Vendor patch released
  • 2026-05-06: disclosed: Public disclosure request submitted
  • 2026-07-09: advisory: NVD publication date

References