Unauthenticated UPnP Vulnerability in Mercusys AC12G Router
CVE-2026-36603

8.1HIGH

Key Information:

Vendor

Mercusys

Vendor
CVE Published:
3 June 2026

What is CVE-2026-36603?

The Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 contains a significant vulnerability that exposes 15 out of 18 UPnP IGD actions without any authentication. This flaw is particularly concerning due to UPnP being enabled by default via the admin interface, which allows any unauthenticated device on the local area network (LAN) to create arbitrary port forwarding rules. Consequently, this may grant unauthorized access to WAN traffic statistics, facilitating potential exploitation by malicious actors.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.