πŸ” CVE Alert

CVE-2026-12495

UNKNOWN 0.0

Stack-Based Buffer Overflow in the Mercusys MB115-4G

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.

CWE CWE-121
Vendor mercusys
Product mb115-4g
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for mercusys mb115-4g

Be the first to know when new unknown vulnerabilities affecting mercusys mb115-4g are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Mercusys / MB115-4G
1.7.0 ≀ 1.9.0

References

NVD β†— CVE.org β†— EPSS Data β†—
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/stack-based-buffer-overflow-mercusys-mb115-4g

Credits

HΓ©ctor Villar Palacios