Uninitialized Buffer Exposure in Mercusys AC12G Firmware
CVE-2026-36613
4.3MEDIUM
What is CVE-2026-36613?
The Mercusys AC12G (EU) V1 device running firmware version AC12G(EU)_V1_200909 is susceptible to a vulnerability that causes it to return 128 bytes of uninitialized internal buffer contents when it processes HTTP POST requests directed at undefined paths. This flaw can potentially expose sensitive server state information to unauthenticated attackers on the adjacent network, posing a significant security risk.
