Hardcoded Credentials in Mercusys AC12G Router Firmware
CVE-2026-36616

5.9MEDIUM

Key Information:

Vendor

Mercusys

Vendor
CVE Published:
3 June 2026

What is CVE-2026-36616?

The Mercusys AC12G (EU) V1 router firmware version AC12G(EU)_V1_200909 is subject to a vulnerability due to the presence of hardcoded WiFi driver credentials. These include a RADIUS shared secret, a WPS test key, and a default Pre-Shared Key (PSK) embedded directly within the production firmware binary. This condition could allow unauthorized access to the network and potential exploitation of device features.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.