Executive brief
An undocumented management endpoint in Mercusys AC12G routers allows unauthorized individuals on the same local network to view internal memory contents. This flaw could expose sensitive technical data about the router's operations or other users' web requests, which can be used to plan more advanced attacks. Because the product is at its end-of-life, no official security updates are expected.
Technical details
The HTTP handler for the undocumented /agileconfigreset endpoint fails to properly manage internal buffers, leading to an information disclosure vulnerability. When an unauthenticated attacker sends a POST request to this endpoint, the router returns a malformed response containing 128 bytes of the internal HTTP header parse buffer. This buffer contains null-separated header names and values from the current request and potentially data from other clients' requests due to a shared buffer pool. The vulnerability is confirmed in firmware versions AC12G(EU)_V1_200909 and AC12G(EU)_V1_210128.
Affected products
- Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory