CVE-2026-36610 Details
Description
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, allowing man-in-the-middle interception of DDNS service credentials.
A vulnerability exists in the Mercusys AC12G (EU) V1 router, specifically in the firmware version AC12G(EU)_V1_200909. The router's Dynamic Domain Name System (DDNS) client transmits user credentials, including usernames and passwords, to external DDNS providers over unencrypted HTTP. While the credentials are encoded in Base64 and sent in the 'Authorization: Basic' header, this encoding is easily reversible. The absence of any SSL/TLS implementation in the firmware allows for man-in-the-middle interception of these DDNS service credentials. This vulnerability affects users of DynDNS and No-IP services, as the intercepted credentials could be reused if shared with other services.
Users are advised to implement TLS for all outbound HTTP connections that carry authentication credentials. At a minimum, routers should support HTTPS endpoints for DDNS providers, as both DynDNS and No-IP offer HTTPS.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 3, 2026CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Tymbark7372/MERCUSYS-AC12G/blob/master/advisories/CVE-2026-36610.md | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | CISA-ADP |
| CWE-523 | Unprotected Transport of Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Mercusys AC12G | AC12G(EU)_V1_200909 AC12G(EU)_V1_210128 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | New CVE Received | [email protected] |
Volerion