๐Ÿ” CVE Alert

CVE-2026-36603

HIGH 8.1
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
6th

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddPortMapping and GetExternalIPAddress. UPnP is enabled by default through the admin interface, allowing any unauthenticated LAN device to create arbitrary port forwarding rules and access WAN traffic statistics.

Vendor n/a
Product n/a
Published Jun 3, 2026
Last Updated Jun 5, 2026
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new high vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Tymbark7372/MERCUSYS-AC12G/blob/master/advisories/CVE-2026-36603.md