Uninitialized Buffer Exposure in Mercusys AC12G Firmware
CVE-2026-36613

4.3MEDIUM

Key Information:

Vendor

Mercusys

Vendor
CVE Published:
3 June 2026

What is CVE-2026-36613?

The Mercusys AC12G (EU) V1 device running firmware version AC12G(EU)_V1_200909 is susceptible to a vulnerability that causes it to return 128 bytes of uninitialized internal buffer contents when it processes HTTP POST requests directed at undefined paths. This flaw can potentially expose sensitive server state information to unauthenticated attackers on the adjacent network, posing a significant security risk.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.