Mercusys records
9 published records for vendor mercusys.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-787 Out-of-bounds Write2
- CWE-121 Stack-based Buffer Overflow1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-755 Improper Handling of Exceptional Conditions1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2022-26988No exploit | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` futp-link · tl-wdr7660 firmware · CWE-787 | High7.8 | — | 1.5% | May 10, 2022 |
31Monitor | CVE-2022-26987No exploit | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrastp-link · tl-wdr7660 firmware · CWE-787 | High7.8 | — | 1.5% | May 10, 2022 |
30Monitor | CVE-2021-25811No exploit | MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter.mercusys · mercury x18g firmware | High7.5 | — | 1.6% | Apr 29, 2021 |
27Monitor | CVE-2025-56463No exploit | Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.mercusys · mw305r firmware · CWE-200 | Medium6.8 | — | 0.2% | Sep 26, 2025 |
26Monitor | CVE-2023-52162No exploit | Mercusys MW325R EU V3 (Firmware MW325R(EU)_V3_1.11.0 Build 221019) is vulnerable to a stack-based buffer overflow, which could allow an attaCWE-121 | Medium6.7 | — | 0.6% | Jun 3, 2024 |
25Monitor | CVE-2021-23241Proof of concept | MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bmercusys · mercury x18g firmware · CWE-22 | Medium5.3 | — | 13.3% | Jan 7, 2021 |
24Monitor | CVE-2021-25810No exploit | Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_endmercusys · mercury x18g firmware · CWE-79 | Medium6.1 | — | 1.1% | Apr 29, 2021 |
22Monitor | CVE-2021-23242No exploit | MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpdmercusys · mercury x18g firmware · CWE-22 | Medium5.3 | — | 1.8% | Jan 7, 2021 |
20Monitor | CVE-2023-46297No exploit | An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices.CWE-755 | Medium5.1 | — | 0.2% | May 29, 2024 |
- CVE-2022-2698831Monitor
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` fu
HighCVSS 7.8No exploitEPSS 2%tp-link · tl-wdr7660 firmwareMay 10, 2022
- CVE-2022-2698731Monitor
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePras
HighCVSS 7.8No exploitEPSS 2%tp-link · tl-wdr7660 firmwareMay 10, 2022
- CVE-2021-2581130Monitor
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter.
HighCVSS 7.5No exploitEPSS 2%mercusys · mercury x18g firmwareApr 29, 2021
- CVE-2025-5646327Monitor
Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure.
MediumCVSS 6.8No exploitEPSS 0%mercusys · mw305r firmwareSep 26, 2025
- CVE-2023-5216226Monitor
Mercusys MW325R EU V3 (Firmware MW325R(EU)_V3_1.11.0 Build 221019) is vulnerable to a stack-based buffer overflow, which could allow an atta
MediumCVSS 6.7No exploitEPSS 1%Jun 3, 2024
- CVE-2021-2324125Monitor
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication b
MediumCVSS 5.3Proof of conceptEPSS 13%mercusys · mercury x18g firmwareJan 7, 2021
- CVE-2021-2581024Monitor
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end
MediumCVSS 6.1No exploitEPSS 1%mercusys · mercury x18g firmwareApr 29, 2021
- CVE-2021-2324222Monitor
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd
MediumCVSS 5.3No exploitEPSS 2%mercusys · mercury x18g firmwareJan 7, 2021
- CVE-2023-4629720Monitor
An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices.
MediumCVSS 5.1No exploitEPSS 0%May 29, 2024