Configuration Backup Vulnerability in Mercusys AC12G Router
CVE-2026-36606

7.1HIGH

Key Information:

Vendor

Mercusys

Vendor
CVE Published:
3 June 2026

What is CVE-2026-36606?

The Mercusys AC12G (EU) V1 router features a significant security vulnerability in its firmware, which employs a hardcoded DES key for encrypting configuration backups. This implementation uses single DES in ECB mode, making it susceptible to decryption by attackers. If an unauthorized individual gains access to a backup file, they can decrypt it, thereby exposing critical information such as the admin password, WiFi Pre-Shared Key (PSK), and Dynamic DNS (DDNS) credentials, undermining the overall security of the device.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.