CVE-2026-36608

HIGH

Mercusys AC12G (EU) V1 Firmware AC12G(EU)_V1_200909 - Unauthenticated UPnP Port Forwarding to Admin Interface

Title source: llm
STIX 2.1

Description

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (192.168.1.1) or localhost (127.0.0.1) as InternalClient. An unauthenticated LAN attacker can expose the admin panel to the internet with a single SOAP request.

Scores

CVSS v3 8.8
EPSS 0.0018
EPSS Percentile 7.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-441
Status published
Published Jun 03, 2026
Tracked Since Jun 03, 2026