CVE-2026-12495 PUBLISHED

Stack-Based Buffer Overflow in the Mercusys MB115-4G

Assigner: INCIBE
Reserved: 17.06.2026 Published: 27.07.2026 Updated: 27.07.2026

Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor Mercusys
Product MB115-4G
Versions Default: unaffected
  • affected from 1.7.0 to 1.9.0 (incl.)

Solutions

The vulnerability has been fixed by the Mercusys team in version V1_1.9.0.

Credits

  • Héctor Villar Palacios finder

References

Problem Types

  • CWE-121 Stack-based buffer overflow CWE