CVE-2026-36611
7.3 HIGHMercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without S...
Published: 2026-06-03 · Last updated: 2026-06-04
Severity and scoring
- CVSS
- 7.3 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- CWE
- CWE-200
Description
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory to unauthenticated adjacent network attackers.
Source: NVD
References
Related CVEs
Same CWE
- CVE-2026-47177 — Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support
- CVE-2026-47176 — Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support
- CVE-2026-44486 — Axios is a promise based HTTP client for the browser and Node.js (7.5 HIGH)
- CVE-2026-53912 — Cerebrate before version 1.37 exposed credential material from self-registration requests
- CVE-2026-49219 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.5 MEDIUM)