CVE-2026-36609: High severity MERCUSYS AC12G (EU) V1 vulnerability

Published Jun 3, 2026
·
Updated

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)V1200909 uses a static authentication nonce that does not change between requests from the same source IP. Combined with the predictable XOR-based password encoding (securityEncode function), this allows an attacker to reverse captured authentication tokens to recover the plaintext password.

Affected Software

1 affected component
MERCUSYS AC12G (EU) V1=AC12G(EU)_V1_200909

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Change the authentication implementation so the nonce is randomly generated for each authentication request and do not use the predictable XOR-based securityEncode. Implement a secure challenge-response (e.g., HMAC-based) or other non-reversible authentication encoding.

    Mercusys AC12G (EU) firmware (authentication) nonce_generation / securityEncode = use per-request cryptographically secure random nonce; replace XOR-based encoding
  2. Configuration

    Disable remote/remote-web/WAN management or restrict management access to a small set of trusted IP addresses or require management only over an authenticated VPN.

    Router management interface remote_management = disabled or restricted to trusted IPs/VPN
  3. Compensating control

    Block or firewall off management ports (web UI, SSH, telnet, other admin interfaces) from untrusted networks/ WAN; allow access only from trusted management networks or through a VPN.

  4. Operational

    Rotate administrative credentials on affected Mercusys AC12G devices (change passwords) and enforce strong, unique administrator passwords.

  5. Operational

    Monitor the vendor for a firmware update that addresses the static nonce and XOR-based encoding issue and apply the vendor-supplied firmware patch as soon as it is available.

Event History

Jun 3, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-36609?

CVE-2026-36609 has a severity rating of high, with a CVSS score of 7.3.

2

How does CVE-2026-36609 affect the Mercusys AC12G (EU) V1 router?

CVE-2026-36609 affects the router by allowing attackers to exploit a static authentication nonce coupled with predictable XOR-based password encoding.

3

What can be done to mitigate CVE-2026-36609?

Mitigation for CVE-2026-36609 involves ensuring firmware updates are applied and avoiding the use of predictable passwords.

4

Are there any known exploits for CVE-2026-36609?

As of now, there are no publicly disclosed exploits specifically targeting CVE-2026-36609.

5

Can CVE-2026-36609 lead to unauthorized access?

Yes, CVE-2026-36609 can potentially lead to unauthorized access due to weaknesses in the authentication mechanism.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203