CVE 8.8 HIGH

CVE-2026-36608_CVE-2026-36608

8.8 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (192.168.1.1) or localhost (127.0.0.1) as InternalClient. An unauthenticated LAN attacker can expose the admin panel to the internet with a single SOAP request.

AI Analysis

Unauthenticated LAN attacker can expose admin panel to the internet via UPnP AddPortMapping

Basic Information

ID CVE-2026-36608
Source mitre
Published Jun 3, 2026 at 00:00
Modified Jun 3, 2026 at 18:34

Affected Product

Vendor Mercusys
Product Mercusys AC12G
Version AC12G(EU)_V1_200909
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Mercusys
Product Mercusys AC12G
Version AC12G(EU)_V1_200909

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.