QSearchQSearch

CVE-2026-36615

4.3 MEDIUM

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer ...

Published: 2026-06-03 · Last updated: 2026-06-04

Severity and scoring

CVSS
4.3 MEDIUM
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE
CWE-200

Description

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns internal buffer contents to unauthenticated attackers on the adjacent network.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-47177 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support
  • CVE-2026-47176 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support
  • CVE-2026-44486 Axios is a promise based HTTP client for the browser and Node.js (7.5 HIGH)
  • CVE-2026-53912 Cerebrate before version 1.37 exposed credential material from self-registration requests
  • CVE-2026-49219 ImageMagick is free and open-source software used for editing and manipulating digital images (5.5 MEDIUM)