Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66mf-3gg5-cm75

Опубликовано: 03 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to the login endpoint (code=7). An attacker on the adjacent network can attempt unlimited passwords without triggering account lockout.

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to the login endpoint (code=7). An attacker on the adjacent network can attempt unlimited passwords without triggering account lockout.

EPSS

Процентиль: 8%
0.00181
Низкий

8.8 High

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to the login endpoint (code=7). An attacker on the adjacent network can attempt unlimited passwords without triggering account lockout.

EPSS

Процентиль: 8%
0.00181
Низкий

8.8 High

CVSS3

Дефекты

CWE-307