Executive brief
The Mercusys AC12G router is vulnerable to a denial-of-service attack that disables its management interface. An attacker on the local network can send a small number of incomplete web requests to the device, causing the administration panel and UPnP services to crash permanently. While basic internet routing continues to function, the administrator will be locked out of the settings and cannot recover access without physically unplugging and restarting the router.
Technical details
The Mercusys AC12G (EU) V1 router's HTTP server (port 80) and UPnP service (port 1900) are vulnerable to uncontrolled resource consumption (CWE-400). The HTTP server utilizes a small, fixed connection pool and fails to implement timeouts for incomplete requests. An attacker on the adjacent network can exhaust all available connection slots by opening approximately 50 concurrent TCP connections with slow or incomplete HTTP headers. This results in a persistent crash of the control plane; while the data plane (routing and DNS) remains operational, the web management interface becomes permanently unresponsive. No automatic recovery or watchdog timer is present, necessitating a physical power cycle. The product is reportedly end-of-life with no planned fix.
Affected products
- Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory