Mercusys manufactures a compact line of consumer and small-business networking devices, including routers and mesh systems, that present modest but durable exposure through path-traversal, out-of-bounds write, and cross-site scripting vulnerabilities in their firmware. While severity tends toward the lower end, vulnerabilities affecting the vendor frequently acquire public exploit code, making affected devices attractive targets for remote compromise and pivoting. Defenders should inventory these devices and prioritize patching given their typical role in network perimeter access; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mercusys over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23241MEDIUM MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (for authentication bypass) to the web server, as demonstrate | Jan 7, 2021 | 5.3 | 35 | NO | YES |
CVE-2022-26988HIGH TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote cod | May 10, 2022 | 7.8 | 27 | NO | NO |
CVE-2025-56463MEDIUM Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure. | Sep 26, 2025 | 6.8 | 23 | NO | NO |
CVE-2021-25811HIGH MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is e | Apr 29, 2021 | 7.5 | 23 | NO | NO |
CVE-2022-26987HIGH TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remot | May 10, 2022 | 7.8 | 22 | NO | NO |
CVE-2021-25810MEDIUM Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters. | Apr 29, 2021 | 6.1 | 20 | NO | NO |
CVE-2021-23242MEDIUM MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../conf/template/uhttpd.json URI. | Jan 7, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mercusys.
Media articles that mention a CVE ID that affects a product developed by Mercusys — matched by CVE ID, not by vendor name.