Mercurycom's vulnerability footprint centers on a narrow set of telecommunications and networking hardware products, including the D196G and MR816 device lines and their associated firmware. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurring memory-safety and input-handling weaknesses—buffer overflows, improper authentication, path traversal, and cross-site scripting—that are characteristic of embedded network device codebases. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mercurycom over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27825HIGH A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL. | May 29, 2023 | 7.5 | 37 | NO | YES |
CVE-2026-35903CRITICAL MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial | Apr 27, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-50401CRITICAL Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password. | Dec 16, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-50398CRITICAL Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter fac_password. | Dec 16, 2025 | 9.8 | 33 | NO | NO |
CVE-2012-4999MEDIUM Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) I | Sep 19, 2012 | 6.1 | 31 | NO | YES |
CVE-2023-46518CRITICAL Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB. | Oct 25, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-31256HIGH A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rts | Apr 27, 2026 | 7.5 | 28 | NO | NO |
CVE-2022-31849HIGH MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request. | Jun 16, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-35902MEDIUM The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid auth | Apr 27, 2026 | 6.2 | 25 | NO | NO |
CVE-2025-65288MEDIUM A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively long hostnames from LAN hosts without proper | Dec 9, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mercurycom.
Media articles that mention a CVE ID that affects a product developed by Mercurycom — matched by CVE ID, not by vendor name.