216.73.217.172

CVE-2026-36609

· Published 03/06/2026 18:16 · Modified 04/06/2026 15:41

Labels: CVE-2026-36609 2026-06-03CVE-2026-36609CWE-327[email protected]

Essential information

Published
03/06/2026 18:16
Modified
04/06/2026 15:41
Author
Creator
CVSS
7.3 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change between requests from the same source IP. Combined with the predictable XOR-based password encoding (securityEncode function), this allows an attacker to reverse captured authentication tokens to recover the plaintext password.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mercusys / ac12g cpe:2.3:a:mercusys:ac12g:*:*:*:*:*:*:*:*

References