Static Authentication Vulnerability in Mercusys AC12G Router
CVE-2026-36609
7.3HIGH
What is CVE-2026-36609?
The Mercusys AC12G (EU) V1 router contains a security flaw due to the use of a static authentication nonce that remains unchanged for requests from the same source IP address. This design flaw, coupled with a vulnerability in the XOR-based password encoding mechanism employed within the securityEncode function, enables an attacker to intercept and reverse-engineer authentication tokens. As a result, they could potentially recover the plaintext passwords, leading to unauthorized access and compromise of the device.
