CVE-2026-78860: High severity MERCUSYS AC12 V2 vulnerability
Published Oct 5, 2026
·Updated
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext
Affected Software
1 affected component
MERCUSYS AC12 V2
Event History
Oct 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as requiring a local attacker. The provided information does not indicate that it can be exploited remotely over the network.
2
What security weakness enables code execution?
The issue involves information being stored in plaintext. The referenced advisory also identifies missing firmware encryption and secure-boot mechanisms.