CVE-2026-12495: Mercusys MB115-4g
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G device's web interface. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and the httpd process to crash, resulting in a denial of service for the web administration service.
Affected products
- Mercusys MB115-4g: from 1.7.0, up to and including 1.9.0
Published 2026-07-27. Last modified 2026-07-28.