DNS Resolver Disclosure in Mercusys AC12G by Mercusys
CVE-2026-36618
4.3MEDIUM
What is CVE-2026-36618?
The Mercusys AC12G (EU) V1 router, when running firmware AC12G(EU)_V1_200909, is susceptible to an information disclosure vulnerability through CHAOS TXT queries to version.bind. This flaw allows attackers to obtain the version information of the router's DNS resolver software, specifically unbound version 1.22.0. By exploiting this vulnerability, an attacker can gain insight into the router's software environment, potentially leading to targeted attacks against known vulnerabilities associated with that software.
