Junglewise Threat Intelligence

CVE-2026-36616: Mercusys AC12G hardcoded WiFi credentials in firmware

CVE-2026-36616 · Severity: info · CVSS 6.1 · Published 2026-06-03

Technologies: Mercusys AC12G (EU) V1, Mercusys AC12G. Vendors: Mercusys.

Executive brief

The Mercusys AC12G wireless router contains hardcoded development credentials and test keys within its production firmware. An attacker within wireless range could potentially impersonate authentication servers or gain unauthorized access to the network if the device reverts to these insecure default settings. This poses a risk to the privacy of the network traffic and the overall security of the connected environment.

Technical details

The vulnerability stems from the inclusion of development and test credentials (CWE-798) within the MediaTek/Ralink WiFi driver configuration template of the production firmware binary. Specifically, the firmware includes a hardcoded RADIUS shared secret ('ralink'), a WPS test key ('scaptest'), and a default AP Client PSK ('12345678'). These credentials may become active if configuration fails or if specific wireless modes are enabled without explicit user-defined keys. Additionally, the firmware contains format strings that log WiFi keys in plaintext to debug or serial outputs, further risking credential exposure. The product is reportedly end-of-life, and no official patch is expected.

Affected products

  • Mercusys AC12G (EU) V1 AC12G(EU)_V1_200909, AC12G(EU)_V1_210128

Timeline

  • 2026-06-03: advisory: NVD and researcher advisory published

References

Related threats