Junglewise Threat Intelligence

CVE-2026-36613: Mercusys AC12G Information Disclosure in HTTP Server

CVE-2026-36613 · Severity: info · CVSS 5.3 · Published 2026-06-03

Technologies: Mercusys AC12G (EU) V1. Vendors: Mercusys.

Executive brief

The Mercusys AC12G wireless router contains a security flaw in its web management interface. When the router receives a specific type of network request to a non-existent page, it accidentally responds with fragments of its internal memory instead of an error message. This could allow an attacker on the same local network to see sensitive technical data or information from previous user sessions, potentially aiding in more complex attacks.

Technical details

The VxWorks-based HTTP server on affected Mercusys AC12G routers fails to return standard HTTP error responses (like 404 Not Found) for unrecognized request paths or invalid TDDP operation codes. Instead, the server responds with 128 bytes of raw internal memory from the header parsing buffer. If a POST body is included, the device performs an out-of-bounds read, leaking an additional 67 bytes from adjacent heap memory. This vulnerability allows an unauthenticated attacker on the adjacent network (LAN) to capture internal server state and fragments of previous HTTP operations. Because the device lacks ASLR, any leaked memory addresses are stable, which may facilitate further exploitation. No fix is planned as the product is reportedly end-of-life.

Affected products

  • Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128

Timeline

  • 2026-06-03: disclosed: Initial disclosure and NVD publication

References

Related threats