CVE-2026-36607: High severity MERCUSYS AC12G (EU) V1 vulnerability
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)V1200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to the login endpoint (code=7). An attacker on the adjacent network can attempt unlimited passwords without triggering account lockout.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the device so the TDDP password change endpoint (code=10) enforces the same rate limiting and account lockout behavior that is applied to the login endpoint (code=7) to prevent unauthenticated brute-force attempts.
Mercusys AC12G (EU) V1 router (firmware AC12G(EU)_V1_200909) TDDP password change endpoint (code=10) rate limiting = same as login endpoint (code=7) - Configuration
If the TDDP password change endpoint (code=10) is not required, disable it or otherwise remove public/adjacent-network accessibility; alternatively restrict it to trusted/management interfaces only.
Mercusys AC12G (EU) V1 router (firmware AC12G(EU)_V1_200909) TDDP password change endpoint (code=10) enabled = disabled (if not required) - Compensating control
Restrict access to the TDDP password change endpoint (code=10) from adjacent or untrusted networks using firewall rules, VLAN segmentation, or access control lists; allow only trusted IPs or management networks to reach the endpoint.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36607?
CVE-2026-36607 has a high severity score of 8.8 according to CVSS 3.1.
How does CVE-2026-36607 affect the Mercusys AC12G (EU) V1 router?
CVE-2026-36607 allows unauthenticated brute-force attacks via the TDDP password change endpoint, which does not implement rate limiting.
Who can exploit CVE-2026-36607?
An attacker on the adjacent network can exploit CVE-2026-36607 due to the lack of rate limiting on the vulnerable endpoint.
What is the risk associated with CVE-2026-36607?
The risk associated with CVE-2026-36607 includes potential unauthorized access to the Mercusys AC12G (EU) V1 router.
How can I mitigate the risks of CVE-2026-36607?
To mitigate the risks of CVE-2026-36607, it is advised to apply firmware updates that address the vulnerability and enforce strong credentials.