Configuration Backup Vulnerability in Mercusys AC12G Router
CVE-2026-36606
7.1HIGH
What is CVE-2026-36606?
The Mercusys AC12G (EU) V1 router features a significant security vulnerability in its firmware, which employs a hardcoded DES key for encrypting configuration backups. This implementation uses single DES in ECB mode, making it susceptible to decryption by attackers. If an unauthorized individual gains access to a backup file, they can decrypt it, thereby exposing critical information such as the admin password, WiFi Pre-Shared Key (PSK), and Dynamic DNS (DDNS) credentials, undermining the overall security of the device.
