PT-2026-45999 · Undefined · Undefined

Published

2026-06-03

·

Updated

2026-06-03

·

CVE-2026-36611

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Mercusys AC12G (EU) V1 with firmware AC12G(EU) V1 200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory to unauthenticated adjacent network attackers.

Exploit

Related Identifiers

CVE-2026-36611

Affected Products

Undefined