-
Pre-Auth RCE in TP-Link & Mercusys 4G Routers: One Character From Code Execution – Part 2 (CVE-2026-75118)
Note on prior work and attribution The stack overflow described in this post was first discovered and reported by Héctor Villar Palacios for the Mercusys MB115-4G on the 22nd of February 2026, registered as CVE-2026-12495. His writeup can be found here. Credit for the discovery is his. I independently rediscovered the vulnerability in July 2026,…
-
Root Shell and Firmware Extraction on a Cheap TP-Link/Mercusys 4G Router – Part 1 (CVE-2026-75118)
Introduction While searching for cheap routers on Amazon to reverse engineer, I stumbled upon Mercusys, a fairly unknown brand. Mercusys is a Chinese brand affiliated to TP-Link. They have product lines which highly resembles those of TP-Link such as routers, switches, and various other IoT products. Reverse engineering of their products has been done only…