PT-2026-45999 · Undefined · Undefined
Published
2026-06-03
·
Updated
2026-06-03
·
CVE-2026-36611
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Mercusys AC12G (EU) V1 with firmware AC12G(EU) V1 200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory to unauthenticated adjacent network attackers.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined