Executive brief
The Mercusys AC12G router fails to encrypt login credentials when connecting to Dynamic DNS (DDNS) services. Because the device sends this information over the open internet in a readable format, anyone positioned between the router and the service provider—such as an ISP or a malicious actor on the same network—can steal the account credentials. This could lead to unauthorized access to the user's DDNS account and potential security risks if the same password is used for other services.
Technical details
The DDNS client module in Mercusys AC12G (EU) V1 firmware (versions 200909 and 210128) lacks a TLS implementation, forcing all outbound DDNS updates to occur over plaintext HTTP. Credentials for providers like DynDNS and No-IP are sent using the 'Authorization: Basic' header, which utilizes Base64 encoding—a reversible format that provides no actual secrecy. An attacker with man-in-the-middle (MITM) capabilities, such as an ISP or an entity on an upstream network, can intercept these packets and decode the username and password. The vendor has reportedly designated the product as end-of-life, meaning no official security patches are expected.
Affected products
- Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory