Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (192.168.1.1) or localhost (127.0.0.1) as InternalClient. An unauthenticated LAN attacker can expose the admin panel to the internet with a single SOAP request.
References
Configurations
No configuration.
History
03 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-441 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
03 Jun 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-03 18:16
Updated : 2026-06-04 15:41
NVD link : CVE-2026-36608
Mitre link : CVE-2026-36608
CVE.ORG link : CVE-2026-36608
JSON object : View
Products Affected
No product.
CWE
CWE-441
Unintended Proxy or Intermediary ('Confused Deputy')
