Hardcoded Credentials in Mercusys AC12G Router Firmware
CVE-2026-36616
5.9MEDIUM
What is CVE-2026-36616?
The Mercusys AC12G (EU) V1 router firmware version AC12G(EU)_V1_200909 is subject to a vulnerability due to the presence of hardcoded WiFi driver credentials. These include a RADIUS shared secret, a WPS test key, and a default Pre-Shared Key (PSK) embedded directly within the production firmware binary. This condition could allow unauthorized access to the network and potential exploitation of device features.
