CVE-2026-36616: Medium severity MERCUSYS AC12G (EU) V1 vulnerability
Mercusys AC12G (EU) V1 with firmware AC12G(EU)V1200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS test key, and default PSK embedded in the production firmware binary.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Mercusys AC12G (EU) V1 (firmware AC12G(EU)_V1_200909)from your environment.Remove the affected device from production networks and replace it with hardware or firmware that does not contain hardcoded credentials.
- Configuration
Disable WPS on the device to mitigate use of the hardcoded WPS test key embedded in the firmware.
Mercusys AC12G (EU) V1 (firmware AC12G(EU)_V1_200909) WPS = disabled - Compensating control
Isolate the device from sensitive networks: place it in a dedicated VLAN, restrict management access to trusted IPs, and block RADIUS-related ports (e.g., UDP 1812/1813) and Wi‑Fi access to prevent use of the hardcoded RADIUS shared secret and default PSK.
- Operational
Inventory your environment to locate any devices running firmware AC12G(EU)_V1_200909, plan their replacement, and monitor for signs of credential abuse originating from these devices.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-36616?
CVE-2026-36616 has a severity rating of medium with a score of 5.9 according to the CVSS 3.1 standard.
How do I fix CVE-2026-36616?
To fix CVE-2026-36616, users should update their Mercusys AC12G (EU) V1 firmware to the latest version that addresses this vulnerability.
What are the risks associated with CVE-2026-36616?
The risks associated with CVE-2026-36616 include unauthorized access to the network due to hardcoded WiFi driver credentials and exposure of sensitive information.
What devices are affected by CVE-2026-36616?
CVE-2026-36616 specifically affects the Mercusys AC12G (EU) V1 router model with firmware AC12G(EU)_V1_200909.
What type of vulnerability is CVE-2026-36616?
CVE-2026-36616 is a vulnerability related to hardcoded credentials, which can lead to increased risk of network compromise.