DNS Resolver Disclosure in Mercusys AC12G by Mercusys
CVE-2026-36618

4.3MEDIUM

Key Information:

Vendor

Mercusys

Status
Vendor
CVE Published:
3 June 2026

What is CVE-2026-36618?

The Mercusys AC12G (EU) V1 router, when running firmware AC12G(EU)_V1_200909, is susceptible to an information disclosure vulnerability through CHAOS TXT queries to version.bind. This flaw allows attackers to obtain the version information of the router's DNS resolver software, specifically unbound version 1.22.0. By exploiting this vulnerability, an attacker can gain insight into the router's software environment, potentially leading to targeted attacks against known vulnerabilities associated with that software.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.