VYPR
Medium severity4.3NVD Advisory· Published Jun 3, 2026· Updated Jun 3, 2026

CVE-2026-36613

CVE-2026-36613

Description

Mercusys AC12G routers leak 128 bytes of uninitialized buffer data and 67 bytes of heap memory via unauthenticated HTTP POST requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Mercusys AC12G routers leak 128 bytes of uninitialized buffer data and 67 bytes of heap memory via unauthenticated HTTP POST requests.

Vulnerability

The VxWorks HTTP server in Mercusys AC12G (EU) V1, specifically firmware versions AC12G(EU)_V1_200909 and AC12G(EU)_V1_210128, fails to return proper HTTP error responses for unrecognized request paths or invalid codes. Instead, it returns 128 bytes of raw internal memory, including the header parsing buffer, when receiving HTTP POST requests to undefined paths [1].

Exploitation

An unauthenticated attacker on the adjacent network can trigger this vulnerability by sending an HTTP POST request to an unrecognized path, such as /admin, /config, /firmware, or a path with an invalid code like POST /?code=N where N is outside the valid handler range. The response will contain raw buffer data before any HTTP status line, and if a POST body is included, an additional 67 bytes beyond the POST body buffer boundary will be read from adjacent heap memory [1].

Impact

Successful exploitation exposes 128 bytes of uninitialized internal server state, including key-value pairs from processed HTTP headers. Additionally, an out-of-bounds read of 67 bytes beyond the POST body buffer can leak fragments of HTTP response templates from previous operations stored in adjacent heap memory. This disclosure affects unauthenticated adjacent network attackers and exposes sensitive server state [1].

Mitigation

This vulnerability affects Mercusys AC12G (EU) V1 devices with firmware AC12G(EU)_V1_200909 and AC12G(EU)_V1_210128. The product is end-of-life, and no fix is planned. There are no workarounds mentioned in the available references [1].

AI Insight generated on Jun 3, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1