Router Vulnerability in Mercusys AC12G Allows Unauthenticated Access
CVE-2026-36608

8.8HIGH

Key Information:

Vendor

Mercusys

Vendor
CVE Published:
3 June 2026

What is CVE-2026-36608?

The Mercusys AC12G (EU) V1 router's firmware allows malicious actors to exploit UPnP functionality by forwarding external ports to the router's admin interface. This can be achieved by sending a SOAP request that designates the router's own internal IP or localhost. As a result, an unauthenticated attacker within the local network can expose the admin panel to the internet, potentially leading to unauthorized administrative access.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.