CVE-2025-65288: Mercurycom MR816 Firmware

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively long hostnames from LAN hosts without proper length validation. The affected code performs unchecked copies/concatenations into fixed-size buffers. A crafted long hostname can overflow the buffer, cause a crash (DoS) and potentially enabling remote code execution.

Affected products

  • Mercurycom MR816 Firmware: version 081c3114_4.8.7 only

Published 2025-12-09. Last modified 2026-06-17.