Executive brief
The Mercusys AC12G wireless router contains a security flaw in its Wi-Fi Protected Setup (WPS) feature, which is used to easily connect devices to Wi-Fi. The device uses a predictable security PIN based on its hardware address and does not sufficiently block repeated incorrect guesses. If an attacker is within range and the WPS feature is activated, they could quickly guess the PIN to gain unauthorized access to the home or office network and its connected devices.
Technical details
The Mercusys AC12G (EU) V1 router (firmware versions 200909 and 210128) implements WPS 2.0 with insecure defaults. The AP PIN is deterministically derived from the BSSID MAC address using a known Ralink/MediaTek algorithm, making it predictable to attackers. Furthermore, the device's lockout policy is insufficient, only triggering a 60-second lockout after 10 failed attempts. While WPS 2.0 requires user activation (via button or UI) for the PIN exchange, an attacker within radio range can exploit the predictable PIN to gain immediate access to the WPA/WPA2 credentials once the session is active. No fix is planned as the product is reportedly end-of-life.
Affected products
- Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128
Timeline
- 2026-06-03: disclosed: Initial disclosure via GitHub and NVD publication.