Junglewise Threat Intelligence

CVE-2026-36615: Mercusys AC12G information disclosure in /agileconfigreset endpoint

CVE-2026-36615 · Severity: info · CVSS 4.3 · Published 2026-06-03

Technologies: Mercusys AC12G (EU) V1, Mercusys AC12G. Vendors: Mercusys.

Executive brief

An undocumented management endpoint in Mercusys AC12G routers allows unauthorized individuals on the same local network to view internal memory contents. This flaw could expose sensitive technical data about the router's operations or other users' web requests, which can be used to plan more advanced attacks. Because the product is at its end-of-life, no official security updates are expected.

Technical details

The HTTP handler for the undocumented /agileconfigreset endpoint fails to properly manage internal buffers, leading to an information disclosure vulnerability. When an unauthenticated attacker sends a POST request to this endpoint, the router returns a malformed response containing 128 bytes of the internal HTTP header parse buffer. This buffer contains null-separated header names and values from the current request and potentially data from other clients' requests due to a shared buffer pool. The vulnerability is confirmed in firmware versions AC12G(EU)_V1_200909 and AC12G(EU)_V1_210128.

Affected products

  • Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory

References

Related threats