Executive brief
The Mercusys AC12G router uses a weak, hardcoded password to encrypt its configuration backup files. If an attacker obtains one of these backup files, they can easily decrypt it to reveal sensitive information such as the administrator password, Wi-Fi keys, and internet service credentials. This could lead to a full takeover of the device and the local network it manages.
Technical details
The configuration backup/restore module in Mercusys AC12G (EU) V1 firmware (specifically versions 200909 and 210128) utilizes a hardcoded DES key (0x478DA50BF9E3D2CF) in ECB mode. The encryption process involves proprietary TP-Link LZ compression followed by single DES-ECB encryption with a 16-byte 'SDMP_CONF_V004' header. Because the key is static and shared across multiple TP-Link and Mercusys product lines, an attacker who obtains a backup file can decrypt it without further authentication. Decrypted contents include plaintext admin passwords, WPA2 pre-shared keys, PPPoE credentials, and DDNS account details. No fix is planned as the product is reportedly end-of-life.
Affected products
- Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory