Executive brief
The Mercusys AC12G is a wireless router used for home and small office networking. A security flaw in its UPnP service allows an attacker on the same local network to view small fragments of the device's internal memory. This could potentially expose sensitive technical information or data from previous network requests, though the device is now end-of-life and unlikely to receive a fix.
Technical details
The vulnerability is an information disclosure (CWE-200) and out-of-bounds read (CWE-125) within the UPnP HTTP server on port 1900. When the server receives a POST request to any endpoint (such as /ipc, /ifc, or /l3f) without a SOAPAction header, it fails to return a standard HTTP error and instead returns 128 bytes of an uninitialized internal buffer. This buffer can contain null-separated header key-value pairs from the current request, fragments of HTTP response templates, or data from previous requests due to a shared response buffer pool. The attack requires no authentication but must be performed from an adjacent network (LAN). The product is reportedly end-of-life with no planned patch.
Affected products
- Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory