Weak Lockout Policy in Mercusys AC12G Router
CVE-2026-36612

6.4MEDIUM

Key Information:

Vendor

Mercusys

Vendor
CVE Published:
3 June 2026

What is CVE-2026-36612?

The Mercusys AC12G router features a default configuration that enables WPS 2.0 with an inadequate lockout policy. Specifically, the device allows users 10 consecutive attempts to connect via WPS before initiating a lockout period of only 60 seconds. This design flaw may allow unauthorized users to exploit the feature, potentially compromising the security of the network. It is crucial for users to implement additional security measures or disable WPS to safeguard their devices.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.