CVE-2026-36608

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (192.168.1.1) or localhost (127.0.0.1) as InternalClient. An unauthenticated LAN attacker can expose the admin panel to the internet with a single SOAP request.
Configurations

No configuration.

History

03 Jun 2026, 19:16

Type Values Removed Values Added
CWE CWE-441
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

03 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-03 18:16

Updated : 2026-06-04 15:41


NVD link : CVE-2026-36608

Mitre link : CVE-2026-36608

CVE.ORG link : CVE-2026-36608


JSON object : View

Products Affected

No product.

CWE
CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')