Executive brief
The Mercusys AC12G wireless router contains a security flaw in its web management interface. When the router receives a specific type of network request to a non-existent page, it accidentally responds with fragments of its internal memory instead of an error message. This could allow an attacker on the same local network to see sensitive technical data or information from previous user sessions, potentially aiding in more complex attacks.
Technical details
The VxWorks-based HTTP server on affected Mercusys AC12G routers fails to return standard HTTP error responses (like 404 Not Found) for unrecognized request paths or invalid TDDP operation codes. Instead, the server responds with 128 bytes of raw internal memory from the header parsing buffer. If a POST body is included, the device performs an out-of-bounds read, leaking an additional 67 bytes from adjacent heap memory. This vulnerability allows an unauthenticated attacker on the adjacent network (LAN) to capture internal server state and fragments of previous HTTP operations. Because the device lacks ASLR, any leaked memory addresses are stable, which may facilitate further exploitation. No fix is planned as the product is reportedly end-of-life.
Affected products
- Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128
Timeline
- 2026-06-03: disclosed: Initial disclosure and NVD publication