Junglewise Threat Intelligence

CVE-2026-36618: Mercusys AC12G information disclosure in DNS resolver

CVE-2026-36618 · Severity: info · CVSS 3.7 · Published 2026-06-03

Technologies: Mercusys AC12G (EU) V1. Vendors: Mercusys.

Executive brief

The Mercusys AC12G router incorrectly reveals its internal DNS software version and hostname to any device on the local network. While this does not directly allow an attacker to take over the device, it provides them with specific technical details that can be used to plan more sophisticated attacks. This model is currently end-of-life, meaning the manufacturer does not plan to release a security update to fix this behavior.

Technical details

The Mercusys AC12G (EU) V1 router's DNS resolver (Unbound 1.22.0) is configured to respond to CHAOS class TXT queries for 'version.bind' and 'hostname.bind'. An attacker on the local area network (LAN) can send these queries to the router to receive the exact software version and the internal hostname ('mms-unbound'). This information exposure (CWE-200) allows an adversary to identify the specific device type and research known vulnerabilities for that particular version of Unbound. The manufacturer has reportedly designated this product as end-of-life, and no official patch is expected.

Affected products

  • Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128

Timeline

  • 2026-06-03: advisory: NVD and researcher advisory published

References

Related threats