
Discovery of Pre-Auth Stack Buffer Overflow Vulnerability in Amazon's Best-Selling Router
hardware_hackingfirmware_analysisbuffer_overflowvulnerabilityrouter_securityreverse_engineeringCVE
The post details the discovery of a pre-authentication stack buffer overflow vulnerability (CVE-2026-12495) in the Mercusys MB115-4G router, a top-selling device on Amazon. The vulnerability was identified through hardware hacking and firmware analysis. The write-up documents the process of reverse-engineering the router’s firmware to uncover the flaw.