CVE-2026-36612: Medium severity MERCUSYS AC12G (EU) V1 vulnerability
Mercusys AC12G (EU) V1 with firmware AC12G(EU)V1200909 enables WPS 2.0 by default with a weak lockout policy (60-second lockout after 10 attempts).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Adjust the WPS 2.0 weak lockout policy by changing it to a stronger lockout configuration (the device currently uses a 60-second lockout after 10 attempts).
Mercusys AC12G (EU) router firmware WPS 2.0 lockout policy = 60-second lockout after 10 attempts (weak policy) - Configuration
Disable WPS 2.0 on AC12G (EU) firmware AC12G(EU)_V1_200909 instead of leaving it enabled by default.
Mercusys AC12G (EU) router firmware WPS 2.0 (enabled by default) = disable
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36612?
CVE-2026-36612 has a medium severity score of 6.4 according to the CVSS 3.1 system.
How do I fix CVE-2026-36612?
To mitigate CVE-2026-36612, disable WPS 2.0 on the Mercusys AC12G (EU) V1 router in the settings.
What systems are affected by CVE-2026-36612?
CVE-2026-36612 affects the Mercusys AC12G (EU) V1 router with the specified firmware version.
What vulnerability does CVE-2026-36612 address?
CVE-2026-36612 addresses a weak lockout policy in the WPS 2.0 feature, allowing potential unauthorized access.
Is CVE-2026-36612 easily exploitable?
Yes, CVE-2026-36612 is easily exploitable due to the default enabled WPS 2.0 and the insufficient lockout mechanism.