DNS Rebinding Vulnerability in Mercusys AC12G Router
CVE-2026-36604

6.5MEDIUM

Key Information:

Vendor

Mercusys

Vendor
CVE Published:
3 June 2026

What is CVE-2026-36604?

The Mercusys AC12G (EU) V1 router, specifically running firmware AC12G(EU)_V1_200909, is susceptible to a DNS rebinding vulnerability due to its inadequate validation of the HTTP Host header. This flaw allows an attacker to rebind a target domain to the internal IP address of the router, effectively facilitating internet-originating attacks. By exploiting this vulnerability, malicious actors can navigate around CORS (Cross-Origin Resource Sharing) limitations, posing a significant security risk to users.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.