Kernel Memory Exposure in Mercusys AC12G Router
CVE-2026-36602
4.3MEDIUM
What is CVE-2026-36602?
The Mercusys AC12G (EU) V1 router is susceptible to a vulnerability that allows an unauthenticated attacker on the adjacent network to exploit the UPnP GetStatusInfo function, thereby exposing a raw MIPS KSEG0 kernel pointer. This leakage of kernel memory layout information can facilitate further attacks, compromising the security and integrity of the device.
