Description
Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The vulnerability has been fixed by the Mercusys team in version V1_1.9.0.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 27 Jul 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mercusys
Mercusys mb115-4g |
|
| Vendors & Products |
Mercusys
Mercusys mb115-4g |
Mon, 27 Jul 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service. | |
| Title | Stack-Based Buffer Overflow in the Mercusys MB115-4G | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-07-27T10:32:19.167Z
Reserved: 2026-06-17T08:53:55.157Z
Link: CVE-2026-12495
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T12:49:34Z
Weaknesses
-
CWE-121
Stack-based Buffer Overflow