Junglewise Threat Intelligence

CVE-2026-36608: Mercusys AC12G UPnP port forwarding to local admin interface

CVE-2026-36608 · Severity: info · CVSS 9.6 · Published 2026-06-03

Technologies: Mercusys AC12G (EU) V1, Mercusys AC12G. Vendors: Mercusys.

Executive brief

The Mercusys AC12G router contains a security flaw that allows its internal management dashboard to be exposed to the public internet. By sending a single command from within the local network, an attacker can bypass security restrictions and make the router's login page accessible to anyone globally. This significantly increases the risk of unauthorized access, remote takeover, and potential network compromise, especially as the device is reportedly end-of-life and may not receive a fix.

Technical details

The vulnerability exists in the UPnP IGD AddPortMapping action due to insufficient validation of the NewInternalClient parameter. An unauthenticated attacker on the local network (LAN) can submit a SOAP request specifying the router's own LAN IP (192.168.1.1) or localhost (127.0.0.1) as the internal client. This creates a port forwarding rule that maps a WAN-side port to the router's internal HTTP admin interface (typically port 80). When combined with other vulnerabilities like a lack of rate limiting, this allows for remote brute-force attacks against the admin credentials from the internet. The device is reportedly end-of-life, and no official patch is expected.

Affected products

  • Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory

References

Related threats