8.8
/ 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (192.168.1.1) or localhost (127.0.0.1) as InternalClient. An unauthenticated LAN attacker can expose the admin panel to the internet with a single SOAP request.
AI Analysis
Unauthenticated LAN attacker can expose admin panel to the internet via UPnP AddPortMapping
Basic Information
ID
CVE-2026-36608
Source
mitre
Published
Jun 3, 2026 at 00:00
Modified
Jun 3, 2026 at 18:34
Affected Product
Vendor
Mercusys
Product
Mercusys AC12G
Version
AC12G(EU)_V1_200909
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Mercusys
Product
Mercusys AC12G
Version
AC12G(EU)_V1_200909