External risk intelligence

Mercusys MB115-4G Web Interface Stack Buffer Overflow Denial of Service

CVE advisorySeverity: MEDIUM (CVSS 5.3)

CVE-2026-12495

The vulnerability resides in the web administration interface of a network device, which is commonly exposed or accessible via the management port. While home router interfaces are often intended for local access, they are frequently reachable via the WAN or managed remotely, making them a common target for external network-based interaction.

Buffer Overflow

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the web administration interface of Mercusys MB115-4G devices, allowing unauthenticated attackers to crash the system by sending a crafted request. This denial-of-service flaw can disrupt the web administration service.

  • Unauthenticated attackers can crash device administration.
  • Matters because web interfaces are often exposed.
  • Confirm relevance and exposure of this device.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can target the Mercusys MB115-4G device by sending a malicious request to the web interface. This request, designed to exploit a stack buffer overflow in the http_gdpr_decrypt function, can cause the httpd process to crash, leading to a denial of service for the device's web administration.

  • No authentication required to access.
  • Triggered by sending a crafted request.
  • Denial of service for web administration.

Live Threat

Current exploitation, exposure, and threat context

A denial-of-service vulnerability in the web administration interface could disrupt access to the Mercusys MB115-4G device's management service. An unauthenticated attacker could trigger this by sending a specially crafted request to a specific endpoint, potentially causing the web server process to crash. This would make the device's web interface unavailable for legitimate users when supported by the advisory.

  • Web administration service could be disrupted.
  • Specially crafted requests could cause crashes.
  • Device management becomes unavailable.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Mercusys MB115-4G's web interface requires immediate attention from teams responsible for network device management and security. The first practical step is to confirm the presence of this device, assess its accessibility from external networks, and identify the specific owner responsible for its configuration and maintenance to plan for remediation.

  • Network or device management teams own this.
  • Verify external reachability and critical function.
  • Plan vendor engagement or device isolation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Mercusys MB115-4G device?

The Mercusys MB115-4G is a networking device that provides internet connectivity, often utilizing 4G cellular networks for data transmission. It includes a web-based administration interface that allows users to configure settings, monitor network status, and manage security options directly through a browser.

How does CVE-2026-12495 trigger a crash?

This vulnerability is a stack-based buffer overflow, classified as CWE-121. It occurs when the web interface's decryption process attempts to store too much data in a reserved memory area. By sending a malformed request to the login endpoint, an attacker forces the system to overwrite adjacent memory, which crashes the web server process and stops the administration service.

Does any specific action trigger this vulnerability?

An attacker triggers the flaw by sending a specially crafted request specifically to the device's login page. Importantly, this does not require a legitimate user to be logged in or even have an account. The crash is specific to the web administration service, meaning standard network traffic passing through the device for general internet use may continue unaffected.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal identifies this as a critical concern because the vulnerable web interface is often accessible over a network. While meant for local management, these interfaces are frequently reachable from the internet or via wide-area networks, significantly increasing the probability that an unauthorized actor could reach the login endpoint to execute the attack.

What should I do if I use this device?

First, identify if the Mercusys MB115-4G is deployed within your infrastructure and confirm whether its web administration interface is accessible from external networks. If the interface is reachable, consider restricting access to the management page to trusted local networks or VPNs only, and coordinate with your technical team to prioritize monitoring for updates or vendor guidance on hardening the management service.

References