{"schema_version":1,"title":"Mercusys vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 17 vulnerabilities in Mercusys: 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-12495, was published on 27 July 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/mercusys","json_url":"https://junglewise.ai/threats/vendors/mercusys.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/mercusys","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":17,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":17},"latest":[{"cve":"CVE-2026-12495","cvss":9.2,"slug":"cve-2026-12495-mercusys-mb115-4g-stack-buffer-overflow-in-http-gdpr-decrypt","title":"Mercusys MB115-4G stack buffer overflow in http_gdpr_decrypt","severity":"info","exploited":false,"published_at":"2026-07-27T12:16:41.027+00:00","url":"https://junglewise.ai/threats/cve-2026-12495-mercusys-mb115-4g-stack-buffer-overflow-in-http-gdpr-decrypt"},{"cve":"CVE-2026-31267","cvss":4.9,"slug":"cve-2026-31267-mercusys-mw302r-stack-buffer-overflow-in-administrative-web","title":"Mercusys MW302R stack buffer overflow in administrative web interface","severity":"info","exploited":false,"published_at":"2026-07-09T21:16:54.667+00:00","url":"https://junglewise.ai/threats/cve-2026-31267-mercusys-mw302r-stack-buffer-overflow-in-administrative-web"},{"cve":"CVE-2026-36618","cvss":3.7,"slug":"cve-2026-36618-mercusys-ac12g-information-disclosure-in-dns-resolver","title":"Mercusys AC12G information disclosure in DNS resolver","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:23.02+00:00","url":"https://junglewise.ai/threats/cve-2026-36618-mercusys-ac12g-information-disclosure-in-dns-resolver"},{"cve":"CVE-2026-36616","cvss":6.1,"slug":"cve-2026-36616-mercusys-ac12g-hardcoded-wifi-credentials-in-firmware","title":"Mercusys AC12G hardcoded WiFi credentials in firmware","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.887+00:00","url":"https://junglewise.ai/threats/cve-2026-36616-mercusys-ac12g-hardcoded-wifi-credentials-in-firmware"},{"cve":"CVE-2026-36615","cvss":4.3,"slug":"cve-2026-36615-mercusys-ac12g-information-disclosure-in-agileconfigreset","title":"Mercusys AC12G information disclosure in /agileconfigreset endpoint","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.75+00:00","url":"https://junglewise.ai/threats/cve-2026-36615-mercusys-ac12g-information-disclosure-in-agileconfigreset"},{"cve":"CVE-2026-36613","cvss":5.3,"slug":"cve-2026-36613-mercusys-ac12g-information-disclosure-in-http-server","title":"Mercusys AC12G Information Disclosure in HTTP Server","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.617+00:00","url":"https://junglewise.ai/threats/cve-2026-36613-mercusys-ac12g-information-disclosure-in-http-server"},{"cve":"CVE-2026-36612","cvss":6.5,"slug":"cve-2026-36612-mercusys-ac12g-weak-wps-lockout-and-predictable-pin","title":"Mercusys AC12G weak WPS lockout and predictable PIN","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.487+00:00","url":"https://junglewise.ai/threats/cve-2026-36612-mercusys-ac12g-weak-wps-lockout-and-predictable-pin"},{"cve":"CVE-2026-36611","cvss":5.3,"slug":"cve-2026-36611-mercusys-ac12g-uninitialized-buffer-disclosure-in-upnp","title":"Mercusys AC12G uninitialized buffer disclosure in UPnP","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.357+00:00","url":"https://junglewise.ai/threats/cve-2026-36611-mercusys-ac12g-uninitialized-buffer-disclosure-in-upnp"},{"cve":"CVE-2026-36610","cvss":5.9,"slug":"cve-2026-36610-mercusys-ac12g-cleartext-transmission-of-ddns-credentials","title":"Mercusys AC12G cleartext transmission of DDNS credentials","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.223+00:00","url":"https://junglewise.ai/threats/cve-2026-36610-mercusys-ac12g-cleartext-transmission-of-ddns-credentials"},{"cve":"CVE-2026-36609","cvss":7.5,"slug":"cve-2026-36609-mercusys-ac12g-v1-password-recovery-via-static-nonce-and-weak","title":"Mercusys AC12G V1 password recovery via static nonce and weak encoding","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.063+00:00","url":"https://junglewise.ai/threats/cve-2026-36609-mercusys-ac12g-v1-password-recovery-via-static-nonce-and-weak"},{"cve":"CVE-2026-36608","cvss":9.6,"slug":"cve-2026-36608-mercusys-ac12g-upnp-port-forwarding-to-local-admin-interface","title":"Mercusys AC12G UPnP port forwarding to local admin interface","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.923+00:00","url":"https://junglewise.ai/threats/cve-2026-36608-mercusys-ac12g-upnp-port-forwarding-to-local-admin-interface"},{"cve":"CVE-2026-36607","cvss":9.8,"slug":"cve-2026-36607-mercusys-ac12g-brute-force-protection-bypass-in-tddp-endpoint","title":"Mercusys AC12G brute-force protection bypass in TDDP endpoint","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.797+00:00","url":"https://junglewise.ai/threats/cve-2026-36607-mercusys-ac12g-brute-force-protection-bypass-in-tddp-endpoint"},{"cve":"CVE-2026-36606","cvss":7.4,"slug":"cve-2026-36606-mercusys-ac12g-hardcoded-des-key-in-configuration-backup","title":"Mercusys AC12G hardcoded DES key in configuration backup","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.677+00:00","url":"https://junglewise.ai/threats/cve-2026-36606-mercusys-ac12g-hardcoded-des-key-in-configuration-backup"},{"cve":"CVE-2026-36605","cvss":7.5,"slug":"cve-2026-36605-mercusys-ac12g-http-denial-of-service-in-web-management-interface","title":"Mercusys AC12G HTTP denial of service in web management interface","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.55+00:00","url":"https://junglewise.ai/threats/cve-2026-36605-mercusys-ac12g-http-denial-of-service-in-web-management-interface"},{"cve":"CVE-2026-36604","cvss":6.5,"slug":"cve-2026-36604-mercusys-ac12g-dns-rebinding-via-missing-host-header-validation","title":"Mercusys AC12G DNS rebinding via missing Host header validation","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.42+00:00","url":"https://junglewise.ai/threats/cve-2026-36604-mercusys-ac12g-dns-rebinding-via-missing-host-header-validation"},{"cve":"CVE-2026-36603","cvss":8.1,"slug":"cve-2026-36603-mercusys-ac12g-missing-authentication-for-upnp-igd-actions","title":"Mercusys AC12G missing authentication for UPnP IGD actions","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.29+00:00","url":"https://junglewise.ai/threats/cve-2026-36603-mercusys-ac12g-missing-authentication-for-upnp-igd-actions"},{"cve":"CVE-2026-36602","cvss":5.3,"slug":"cve-2026-36602-mercusys-ac12g-kernel-memory-disclosure-in-upnp-getstatusinfo","title":"Mercusys AC12G kernel memory disclosure in UPnP GetStatusInfo","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.15+00:00","url":"https://junglewise.ai/threats/cve-2026-36602-mercusys-ac12g-kernel-memory-disclosure-in-upnp-getstatusinfo"}],"vendor":{"hub":true,"name":"Mercusys","slug":"mercusys","homepage":"https://www.mercusys.com/","description":"Mercusys is a provider of networking devices including routers, range extenders, adapters, and switches.","url":"https://junglewise.ai/threats/vendors/mercusys"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-36607","cvss":9.8,"slug":"cve-2026-36607-mercusys-ac12g-brute-force-protection-bypass-in-tddp-endpoint","title":"Mercusys AC12G brute-force protection bypass in TDDP endpoint","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.797+00:00","url":"https://junglewise.ai/threats/cve-2026-36607-mercusys-ac12g-brute-force-protection-bypass-in-tddp-endpoint"},{"cve":"CVE-2026-36608","cvss":9.6,"slug":"cve-2026-36608-mercusys-ac12g-upnp-port-forwarding-to-local-admin-interface","title":"Mercusys AC12G UPnP port forwarding to local admin interface","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.923+00:00","url":"https://junglewise.ai/threats/cve-2026-36608-mercusys-ac12g-upnp-port-forwarding-to-local-admin-interface"},{"cve":"CVE-2026-12495","cvss":9.2,"slug":"cve-2026-12495-mercusys-mb115-4g-stack-buffer-overflow-in-http-gdpr-decrypt","title":"Mercusys MB115-4G stack buffer overflow in http_gdpr_decrypt","severity":"info","exploited":false,"published_at":"2026-07-27T12:16:41.027+00:00","url":"https://junglewise.ai/threats/cve-2026-12495-mercusys-mb115-4g-stack-buffer-overflow-in-http-gdpr-decrypt"},{"cve":"CVE-2026-36603","cvss":8.1,"slug":"cve-2026-36603-mercusys-ac12g-missing-authentication-for-upnp-igd-actions","title":"Mercusys AC12G missing authentication for UPnP IGD actions","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.29+00:00","url":"https://junglewise.ai/threats/cve-2026-36603-mercusys-ac12g-missing-authentication-for-upnp-igd-actions"},{"cve":"CVE-2026-36609","cvss":7.5,"slug":"cve-2026-36609-mercusys-ac12g-v1-password-recovery-via-static-nonce-and-weak","title":"Mercusys AC12G V1 password recovery via static nonce and weak encoding","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.063+00:00","url":"https://junglewise.ai/threats/cve-2026-36609-mercusys-ac12g-v1-password-recovery-via-static-nonce-and-weak"},{"cve":"CVE-2026-36605","cvss":7.5,"slug":"cve-2026-36605-mercusys-ac12g-http-denial-of-service-in-web-management-interface","title":"Mercusys AC12G HTTP denial of service in web management interface","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.55+00:00","url":"https://junglewise.ai/threats/cve-2026-36605-mercusys-ac12g-http-denial-of-service-in-web-management-interface"},{"cve":"CVE-2026-36606","cvss":7.4,"slug":"cve-2026-36606-mercusys-ac12g-hardcoded-des-key-in-configuration-backup","title":"Mercusys AC12G hardcoded DES key in configuration backup","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.677+00:00","url":"https://junglewise.ai/threats/cve-2026-36606-mercusys-ac12g-hardcoded-des-key-in-configuration-backup"},{"cve":"CVE-2026-36612","cvss":6.5,"slug":"cve-2026-36612-mercusys-ac12g-weak-wps-lockout-and-predictable-pin","title":"Mercusys AC12G weak WPS lockout and predictable PIN","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.487+00:00","url":"https://junglewise.ai/threats/cve-2026-36612-mercusys-ac12g-weak-wps-lockout-and-predictable-pin"},{"cve":"CVE-2026-36604","cvss":6.5,"slug":"cve-2026-36604-mercusys-ac12g-dns-rebinding-via-missing-host-header-validation","title":"Mercusys AC12G DNS rebinding via missing Host header validation","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.42+00:00","url":"https://junglewise.ai/threats/cve-2026-36604-mercusys-ac12g-dns-rebinding-via-missing-host-header-validation"},{"cve":"CVE-2026-36616","cvss":6.1,"slug":"cve-2026-36616-mercusys-ac12g-hardcoded-wifi-credentials-in-firmware","title":"Mercusys AC12G hardcoded WiFi credentials in firmware","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.887+00:00","url":"https://junglewise.ai/threats/cve-2026-36616-mercusys-ac12g-hardcoded-wifi-credentials-in-firmware"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Mercusys AC12G(EU) V1","slug":"ac12g-eu-v1","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ac12g-eu-v1"},{"name":"Mercusys AC12G","slug":"ac12g","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/ac12g"}]}