PatchSiren

Mercusys CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Mercusys CVE published 2026-07-27

CVE-2026-12495

A critical vulnerability, CVE-2026-12495, exists in the Mercusys MB115-4G device due to a stack buffer overflow in the http_gdpr_decrypt function of its web interface. An unauthenticated attacker can exploit this by sending a specially crafted request to the /cgi/login endpoint, causing memory corruption and resulting in a denial of service for the web administration service. This vulnerability has a CVSS [truncated]