Executive brief
The Mercusys AC12G router contains a security flaw in its UPnP service, which is used to automatically configure network settings. An attacker or a compromised device on the local network can use this flaw to create unauthorized port forwarding rules, potentially exposing internal devices to the internet. Additionally, they can disconnect the router from the internet or view sensitive network statistics without needing a password.
Technical details
The Mercusys AC12G (EU) V1 router's UPnP IGD (Internet Gateway Device) implementation on port 1900 exposes 15 out of 18 SOAP actions without authentication. This vulnerability (CWE-306) allows any unauthenticated device on the local area network (LAN) to execute sensitive commands such as AddPortMapping, DeletePortMapping, and ForceTermination. Attackers can exploit this to create arbitrary NAT port forwarding rules, potentially exposing internal services to the WAN, or to perform a denial-of-service by terminating the WAN connection. The service also leaks sensitive information including the WAN IP address and traffic statistics (CWE-200). The product is reportedly end-of-life, and no official patch is expected.
Affected products
- Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128
Timeline
- 2026-06-03: advisory: NVD publication date
- 2026-06-03: disclosed: Public disclosure via GitHub advisory