VYPR
Unrated severityNVD Advisory· Published Jun 3, 2026

CVE-2026-36618

CVE-2026-36618

Description

Mercusys AC12G routers disclose DNS resolver version (unbound 1.22.0) via DNS queries, aiding targeted attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Mercusys AC12G routers disclose DNS resolver version (unbound 1.22.0) via DNS queries, aiding targeted attacks.

Vulnerability

The Mercusys AC12G (EU) V1 router, specifically firmware versions AC12G(EU)_V1_200909 and AC12G(EU)_V1_210128, is vulnerable to information disclosure. The device's DNS resolver, identified as unbound 1.22.0 with the internal hostname "mms-unbound", responds to CHAOS class TXT queries for version.bind and hostname.bind.

Exploitation

An attacker on the local network can send DNS queries to the router, which acts as the default DNS resolver for LAN clients. By querying for version.bind and hostname.bind, the attacker can obtain the exact DNS software version and confirm the device is a Mercusys router.

Impact

Successful exploitation reveals the specific version of the unbound DNS resolver software (1.22.0) and the internal hostname "mms-unbound". This information can assist attackers in researching and targeting known vulnerabilities specific to this version of unbound, and confirms the device's identity.

Mitigation

While a firmware patch is not planned as the product is end-of-life, the unbound DNS resolver can be configured with hide-version: yes and hide-identity: yes to prevent this disclosure. This configuration change is noted in the provided reference [1].

AI Insight generated on Jun 3, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1