Weak Lockout Policy in Mercusys AC12G Router
CVE-2026-36612
6.4MEDIUM
What is CVE-2026-36612?
The Mercusys AC12G router features a default configuration that enables WPS 2.0 with an inadequate lockout policy. Specifically, the device allows users 10 consecutive attempts to connect via WPS before initiating a lockout period of only 60 seconds. This design flaw may allow unauthorized users to exploit the feature, potentially compromising the security of the network. It is crucial for users to implement additional security measures or disable WPS to safeguard their devices.
