mercusys
Top products
Latest CVEs
The 9 most recently published vulnerabilities affecting mercusys.
- CVE-2025-56463Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.6.8
- CVE-2025-7882Mercusys MW301R Login excessive authentication3.1
- CVE-2025-7881Mercusys MW301R Web Interface password recovery2.7
- CVE-2022-26988TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.7.8
- CVE-2022-26987TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.7.8
- CVE-2021-25811MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the devic...7.5
- CVE-2021-25810Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.6.1
- CVE-2021-23241MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrated by the /loginLe...5.3
- CVE-2021-23242MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI.5.3