{"schema_version":1,"title":"Mercusys AC12G(EU) V1 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in Mercusys AC12G(EU) V1: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-36618, was published on 3 June 2026.","url":"https://junglewise.ai/threats/technologies/ac12g-eu-v1","json_url":"https://junglewise.ai/threats/technologies/ac12g-eu-v1.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/ac12g-eu-v1","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":12,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":12},"latest":[{"cve":"CVE-2026-36618","cvss":3.7,"slug":"cve-2026-36618-mercusys-ac12g-information-disclosure-in-dns-resolver","title":"Mercusys AC12G information disclosure in DNS resolver","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:23.02+00:00","url":"https://junglewise.ai/threats/cve-2026-36618-mercusys-ac12g-information-disclosure-in-dns-resolver"},{"cve":"CVE-2026-36616","cvss":6.1,"slug":"cve-2026-36616-mercusys-ac12g-hardcoded-wifi-credentials-in-firmware","title":"Mercusys AC12G hardcoded WiFi credentials in firmware","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.887+00:00","url":"https://junglewise.ai/threats/cve-2026-36616-mercusys-ac12g-hardcoded-wifi-credentials-in-firmware"},{"cve":"CVE-2026-36615","cvss":4.3,"slug":"cve-2026-36615-mercusys-ac12g-information-disclosure-in-agileconfigreset","title":"Mercusys AC12G information disclosure in /agileconfigreset endpoint","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.75+00:00","url":"https://junglewise.ai/threats/cve-2026-36615-mercusys-ac12g-information-disclosure-in-agileconfigreset"},{"cve":"CVE-2026-36613","cvss":5.3,"slug":"cve-2026-36613-mercusys-ac12g-information-disclosure-in-http-server","title":"Mercusys AC12G Information Disclosure in HTTP Server","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.617+00:00","url":"https://junglewise.ai/threats/cve-2026-36613-mercusys-ac12g-information-disclosure-in-http-server"},{"cve":"CVE-2026-36612","cvss":6.5,"slug":"cve-2026-36612-mercusys-ac12g-weak-wps-lockout-and-predictable-pin","title":"Mercusys AC12G weak WPS lockout and predictable PIN","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.487+00:00","url":"https://junglewise.ai/threats/cve-2026-36612-mercusys-ac12g-weak-wps-lockout-and-predictable-pin"},{"cve":"CVE-2026-36611","cvss":5.3,"slug":"cve-2026-36611-mercusys-ac12g-uninitialized-buffer-disclosure-in-upnp","title":"Mercusys AC12G uninitialized buffer disclosure in UPnP","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.357+00:00","url":"https://junglewise.ai/threats/cve-2026-36611-mercusys-ac12g-uninitialized-buffer-disclosure-in-upnp"},{"cve":"CVE-2026-36610","cvss":5.9,"slug":"cve-2026-36610-mercusys-ac12g-cleartext-transmission-of-ddns-credentials","title":"Mercusys AC12G cleartext transmission of DDNS credentials","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.223+00:00","url":"https://junglewise.ai/threats/cve-2026-36610-mercusys-ac12g-cleartext-transmission-of-ddns-credentials"},{"cve":"CVE-2026-36609","cvss":7.5,"slug":"cve-2026-36609-mercusys-ac12g-v1-password-recovery-via-static-nonce-and-weak","title":"Mercusys AC12G V1 password recovery via static nonce and weak encoding","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.063+00:00","url":"https://junglewise.ai/threats/cve-2026-36609-mercusys-ac12g-v1-password-recovery-via-static-nonce-and-weak"},{"cve":"CVE-2026-36608","cvss":9.6,"slug":"cve-2026-36608-mercusys-ac12g-upnp-port-forwarding-to-local-admin-interface","title":"Mercusys AC12G UPnP port forwarding to local admin interface","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.923+00:00","url":"https://junglewise.ai/threats/cve-2026-36608-mercusys-ac12g-upnp-port-forwarding-to-local-admin-interface"},{"cve":"CVE-2026-36607","cvss":9.8,"slug":"cve-2026-36607-mercusys-ac12g-brute-force-protection-bypass-in-tddp-endpoint","title":"Mercusys AC12G brute-force protection bypass in TDDP endpoint","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.797+00:00","url":"https://junglewise.ai/threats/cve-2026-36607-mercusys-ac12g-brute-force-protection-bypass-in-tddp-endpoint"},{"cve":"CVE-2026-36605","cvss":7.5,"slug":"cve-2026-36605-mercusys-ac12g-http-denial-of-service-in-web-management-interface","title":"Mercusys AC12G HTTP denial of service in web management interface","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.55+00:00","url":"https://junglewise.ai/threats/cve-2026-36605-mercusys-ac12g-http-denial-of-service-in-web-management-interface"},{"cve":"CVE-2026-36604","cvss":6.5,"slug":"cve-2026-36604-mercusys-ac12g-dns-rebinding-via-missing-host-header-validation","title":"Mercusys AC12G DNS rebinding via missing Host header validation","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.42+00:00","url":"https://junglewise.ai/threats/cve-2026-36604-mercusys-ac12g-dns-rebinding-via-missing-host-header-validation"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Mercusys AC12G","slug":"ac12g","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/ac12g"}],"technology":{"hub":true,"name":"Mercusys AC12G(EU) V1","slug":"ac12g-eu-v1","vendor":{"name":"Mercusys","slug":"mercusys","url":"https://junglewise.ai/threats/vendors/mercusys"},"aliases":[],"category":"firmware","homepage":"https://www.mercusys.com/en/product/details/ac12g/","repo_url":"https://www.mercusys.com/en/product/details/ac12g/","description":"The AC12G (EU) V1 is the firmware for the Mercusys AC1200 Wireless Gigabit Dual Band Router.","url":"https://junglewise.ai/threats/technologies/ac12g-eu-v1"},"most_severe":[{"cve":"CVE-2026-36607","cvss":9.8,"slug":"cve-2026-36607-mercusys-ac12g-brute-force-protection-bypass-in-tddp-endpoint","title":"Mercusys AC12G brute-force protection bypass in TDDP endpoint","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.797+00:00","url":"https://junglewise.ai/threats/cve-2026-36607-mercusys-ac12g-brute-force-protection-bypass-in-tddp-endpoint"},{"cve":"CVE-2026-36608","cvss":9.6,"slug":"cve-2026-36608-mercusys-ac12g-upnp-port-forwarding-to-local-admin-interface","title":"Mercusys AC12G UPnP port forwarding to local admin interface","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.923+00:00","url":"https://junglewise.ai/threats/cve-2026-36608-mercusys-ac12g-upnp-port-forwarding-to-local-admin-interface"},{"cve":"CVE-2026-36609","cvss":7.5,"slug":"cve-2026-36609-mercusys-ac12g-v1-password-recovery-via-static-nonce-and-weak","title":"Mercusys AC12G V1 password recovery via static nonce and weak encoding","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.063+00:00","url":"https://junglewise.ai/threats/cve-2026-36609-mercusys-ac12g-v1-password-recovery-via-static-nonce-and-weak"},{"cve":"CVE-2026-36605","cvss":7.5,"slug":"cve-2026-36605-mercusys-ac12g-http-denial-of-service-in-web-management-interface","title":"Mercusys AC12G HTTP denial of service in web management interface","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.55+00:00","url":"https://junglewise.ai/threats/cve-2026-36605-mercusys-ac12g-http-denial-of-service-in-web-management-interface"},{"cve":"CVE-2026-36612","cvss":6.5,"slug":"cve-2026-36612-mercusys-ac12g-weak-wps-lockout-and-predictable-pin","title":"Mercusys AC12G weak WPS lockout and predictable PIN","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.487+00:00","url":"https://junglewise.ai/threats/cve-2026-36612-mercusys-ac12g-weak-wps-lockout-and-predictable-pin"},{"cve":"CVE-2026-36604","cvss":6.5,"slug":"cve-2026-36604-mercusys-ac12g-dns-rebinding-via-missing-host-header-validation","title":"Mercusys AC12G DNS rebinding via missing Host header validation","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:21.42+00:00","url":"https://junglewise.ai/threats/cve-2026-36604-mercusys-ac12g-dns-rebinding-via-missing-host-header-validation"},{"cve":"CVE-2026-36616","cvss":6.1,"slug":"cve-2026-36616-mercusys-ac12g-hardcoded-wifi-credentials-in-firmware","title":"Mercusys AC12G hardcoded WiFi credentials in firmware","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.887+00:00","url":"https://junglewise.ai/threats/cve-2026-36616-mercusys-ac12g-hardcoded-wifi-credentials-in-firmware"},{"cve":"CVE-2026-36610","cvss":5.9,"slug":"cve-2026-36610-mercusys-ac12g-cleartext-transmission-of-ddns-credentials","title":"Mercusys AC12G cleartext transmission of DDNS credentials","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.223+00:00","url":"https://junglewise.ai/threats/cve-2026-36610-mercusys-ac12g-cleartext-transmission-of-ddns-credentials"},{"cve":"CVE-2026-36613","cvss":5.3,"slug":"cve-2026-36613-mercusys-ac12g-information-disclosure-in-http-server","title":"Mercusys AC12G Information Disclosure in HTTP Server","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.617+00:00","url":"https://junglewise.ai/threats/cve-2026-36613-mercusys-ac12g-information-disclosure-in-http-server"},{"cve":"CVE-2026-36611","cvss":5.3,"slug":"cve-2026-36611-mercusys-ac12g-uninitialized-buffer-disclosure-in-upnp","title":"Mercusys AC12G uninitialized buffer disclosure in UPnP","severity":"info","exploited":false,"published_at":"2026-06-03T18:16:22.357+00:00","url":"https://junglewise.ai/threats/cve-2026-36611-mercusys-ac12g-uninitialized-buffer-disclosure-in-upnp"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}