Junglewise Threat Intelligence

CVE-2026-36602: Mercusys AC12G kernel memory disclosure in UPnP GetStatusInfo

CVE-2026-36602 · Severity: info · CVSS 5.3 · Published 2026-06-03

Technologies: Mercusys AC12G (EU) V1, Mercusys AC12G. Vendors: Mercusys.

Executive brief

The Mercusys AC12G router, a device used for home and small office networking, contains a security flaw in its UPnP service. An attacker on the local network can retrieve internal memory addresses from the device without needing a password. While this does not directly grant control of the router, it provides critical information that makes it significantly easier for an attacker to develop more advanced exploits to take over the device.

Technical details

An information disclosure vulnerability exists in the UPnP SOAP handler of the Mercusys AC12G (EU) V1 router. The GetStatusInfo action on the WANIPConnection service (port 1900, endpoint /ipc) incorrectly returns a raw MIPS KSEG0 kernel virtual address in the NewConnectionStatus field. This occurs because the handler passes a pointer value through string formatting instead of dereferencing it. An unauthenticated attacker on the adjacent network can use this leaked address to map the kernel memory layout. Since the underlying VxWorks operating system lacks ASLR, these addresses are reliable and can be used to facilitate the development of further exploits, such as buffer overflows, to achieve remote code execution.

Affected products

  • Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory

References

Related threats