PT-2026-45991 · Mercusys · Ac12G

·

CVE-2026-36603

·

Published

2026-06-03

·

Updated

2026-06-05

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mercusys AC12G (EU) V1 version AC12G(EU) V1 200909
Description The device exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddPortMapping and GetExternalIPAddress. Universal Plug and Play (UPnP), a protocol that allows devices to discover each other and establish communication services on a network, is enabled by default. This allows any unauthenticated device on the local area network (LAN) to create arbitrary port forwarding rules and access WAN traffic statistics.
Recommendations Disable UPnP through the admin interface for version AC12G(EU) V1 200909.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-36603

Affected Products

Ac12G