CVE-2026-36606: High severity MERCUSYS AC12G (EU) V1 vulnerability
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)V1200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mode. An attacker who obtains a backup file can decrypt it to recover all stored credentials including admin password, WiFi PSK, and DDNS credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mercusys AC12G (EU)to a version that resolves this vulnerability.Fixed in AC12G(EU)_V1_200909
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36606?
The severity of CVE-2026-36606 is rated high with a score of 7.1 on the CVSS scale.
How does CVE-2026-36606 affect the Mercusys AC12G (EU) V1 router?
CVE-2026-36606 affects the Mercusys AC12G (EU) V1 router by allowing an attacker to decrypt configuration backups encrypted with a hardcoded DES key.
What information can be compromised due to CVE-2026-36606?
An attacker exploiting CVE-2026-36606 can recover stored credentials including the admin password, WiFi PSK, and DDNS credentials.
How do I fix CVE-2026-36606?
To fix CVE-2026-36606, update the router to the latest firmware that addresses the vulnerability.
What encryption method is used in CVE-2026-36606?
CVE-2026-36606 uses single DES in ECB mode for encrypting configuration backups.