CVE-2026-36613
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Jun 03, 2026
Vendor
unknown
Description
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents when receiving HTTP POST requests to undefined paths, exposing server state to unauthenticated adjacent network attackers.