Stack-Based Buffer Overflow in the Mercusys MB115-4G
Mercusys MB115-4G, from version 1.7.0 through MB115-4G(EU)_V1_1.9.0.
INCIBE has coordinated the disclosure of a medium-severity vulnerability affecting the Mercusys MB115-4G, a desktop wireless router from Mercusys. The vulnerability was discovered by Héctor Villar Palacios.
This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:
- CVE-2026-12495: CVSS v4.0: 9.2 | CVSS AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-121
The vulnerability has been fixed by the Mercusys team in version V1_1.9.0.
CVE-2026-12495: Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-12495 | Media | No | Mercusys |



