Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mercurycom

First CVE: Sep 19, 2012Active for: 14 yearsTotal CVEs: 12
37.4
VTI Score
Medium

Mercurycom's vulnerability footprint centers on a narrow set of telecommunications and networking hardware products, including the D196G and MR816 device lines and their associated firmware. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurring memory-safety and input-handling weaknesses—buffer overflows, improper authentication, path traversal, and cross-site scripting—that are characteristic of embedded network device codebases. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mercurycom over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2012
13 years ago
Most Recent CVE
Apr 27, 2026
88 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27825HIGH
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.
May 29, 20237.537NOYES
CVE-2026-35903CRITICAL
MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial
Apr 27, 20269.834NONO
CVE-2025-50401CRITICAL
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter password.
Dec 16, 20259.834NONO
CVE-2025-50398CRITICAL
Mercury D196G d196gv1-cn-up_2020-01-09_11.21.44 is vulnerable to Buffer Overflow in the function sub_404CAEDC via the parameter fac_password.
Dec 16, 20259.833NONO
CVE-2012-4999MEDIUM
Mercury MR804 Router 8.0 3.8.1 Build 101220 Rel.53006nB allows remote attackers to cause a denial of service (service hang) via a crafted string in HTTP header fields such as (1) I
Sep 19, 20126.131NOYES
CVE-2023-46518CRITICAL
Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.
Oct 25, 20239.830NONO
CVE-2026-31256HIGH
A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rts
Apr 27, 20267.528NONO
CVE-2022-31849HIGH
MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.
Jun 16, 20228.828NONO
CVE-2026-35902MEDIUM
The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid auth
Apr 27, 20266.225NONO
CVE-2025-65288MEDIUM
A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively long hostnames from LAN hosts without proper
Dec 9, 20256.522NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
25%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (16.7%)
Network7 (58.3%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network2 (16.7%)
Attack Complexity
Low11 (91.7%)
High0 (0.0%)
Unknown1 (8.3%)
User Interaction
None11 (91.7%)
Unknown1 (8.3%)
Required0 (0.0%)
Privileges Required
Low1 (8.3%)
High1 (8.3%)
None9 (75.0%)
Unknown1 (8.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mercurycom.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mercurycom — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mercurycom's Products

View all 1 CNAs →

Top CWEs