Junglewise Threat Intelligence

CVE-2026-36612: Mercusys AC12G weak WPS lockout and predictable PIN

CVE-2026-36612 · Severity: info · CVSS 6.5 · Published 2026-06-03

Technologies: Mercusys AC12G (EU) V1. Vendors: Mercusys.

Executive brief

The Mercusys AC12G wireless router contains a security flaw in its Wi-Fi Protected Setup (WPS) feature, which is used to easily connect devices to Wi-Fi. The device uses a predictable security PIN based on its hardware address and does not sufficiently block repeated incorrect guesses. If an attacker is within range and the WPS feature is activated, they could quickly guess the PIN to gain unauthorized access to the home or office network and its connected devices.

Technical details

The Mercusys AC12G (EU) V1 router (firmware versions 200909 and 210128) implements WPS 2.0 with insecure defaults. The AP PIN is deterministically derived from the BSSID MAC address using a known Ralink/MediaTek algorithm, making it predictable to attackers. Furthermore, the device's lockout policy is insufficient, only triggering a 60-second lockout after 10 failed attempts. While WPS 2.0 requires user activation (via button or UI) for the PIN exchange, an attacker within radio range can exploit the predictable PIN to gain immediate access to the WPA/WPA2 credentials once the session is active. No fix is planned as the product is reportedly end-of-life.

Affected products

  • Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128

Timeline

  • 2026-06-03: disclosed: Initial disclosure via GitHub and NVD publication.

References

Related threats