Unauthenticated UPnP Vulnerability in Mercusys AC12G Router
CVE-2026-36603
8.1HIGH
What is CVE-2026-36603?
The Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 contains a significant vulnerability that exposes 15 out of 18 UPnP IGD actions without any authentication. This flaw is particularly concerning due to UPnP being enabled by default via the admin interface, which allows any unauthenticated device on the local area network (LAN) to create arbitrary port forwarding rules. Consequently, this may grant unauthorized access to WAN traffic statistics, facilitating potential exploitation by malicious actors.
