Vulnerabilities > CVE-2021-25811 - Unspecified vulnerability in Mercusys Mercury X18G Firmware 1.0.5

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
mercusys

Summary

MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed.

Vulnerable Configurations

Part Description Count
OS
Mercusys
1
Hardware
Mercusys
1