CVE-2026-36616 Details
Description
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS test key, and default PSK embedded in the production firmware binary.
A vulnerability exists in the Mercusys AC12G (EU) V1 router, specifically in the firmware version AC12G(EU)_V1_200909. This vulnerability involves hardcoded WiFi driver credentials embedded in the production firmware binary. The credentials include a RADIUS shared secret, a WPS test key, and a default Pre-Shared Key (PSK). These hardcoded credentials, left over from development and testing, could be activated under certain conditions, such as a failure in configuration or the enabling of specific wireless modes without proper key management.
No official fix is planned, but it is recommended to remove all development and test credentials from the production firmware, require explicit RADIUS key configuration when WPA-Enterprise is enabled, remove development infrastructure IP addresses from production builds, and disable or compile-gate plaintext credential logging.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 3, 2026CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Tymbark7372/MERCUSYS-AC12G/blob/master/advisories/CVE-2026-36616.md | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | CISA-ADP |
| CWE-798 | Use of Hard-coded Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Mercusys AC12G | AC12G(EU)_V1_200909 AC12G(EU)_V1_210128 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | New CVE Received | [email protected] |
Volerion