Junglewise Threat Intelligence

CVE-2026-36607: Mercusys AC12G brute-force protection bypass in TDDP endpoint

CVE-2026-36607 · Severity: info · CVSS 9.8 · Published 2026-06-03

Technologies: Mercusys AC12G (EU) V1. Vendors: Mercusys.

Executive brief

The Mercusys AC12G router contains a security flaw that allows an attacker on the same network to guess the administrator password without being locked out. While the standard login page limits failed attempts, a secondary management feature lacks these protections, allowing for rapid, automated password guessing. If successful, an attacker gains full control over the router, enabling them to monitor internet traffic, change network settings, or redirect users to malicious websites.

Technical details

The vulnerability exists in the TDDP (TP-Link Device Debug Protocol) HTTP interface of the Mercusys AC12G (EU) V1 router. While the standard login endpoint (code=7) implements a lockout mechanism after five failed attempts, the password change endpoint (code=10) validates the administrator password without any rate limiting or lockout. An attacker on the adjacent network can perform unauthenticated brute-force attacks at speeds of 700-1500 attempts per second. The password encoding mechanism (orgAuthPwd) uses a static XOR salt and alphabet substitution documented in the router's client-side JavaScript, making it trivial for an attacker to automate the attack. Successful exploitation grants full administrative access. No fix is planned as the device is reportedly end-of-life.

Affected products

  • Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory

References

Related threats