Stack-Based Buffer Overflow in the Mercusys MB115-4G

Posted date 27/07/2026
Identificador
INCIBE-2026-510
Importance
5 - Critical
Affected Resources

Mercusys MB115-4G, from version 1.7.0 through MB115-4G(EU)_V1_1.9.0.

Description

INCIBE has coordinated the disclosure of a medium-severity vulnerability affecting the Mercusys MB115-4G, a desktop wireless router from Mercusys. The vulnerability was discovered by Héctor Villar Palacios.

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:

  • CVE-2026-12495: CVSS v4.0: 9.2 | CVSS AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N | CWE-121
Solution

The vulnerability has been fixed by the Mercusys team in version V1_1.9.0.

Detail

CVE-2026-12495: Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-12495 Media No Mercusys
References list