


Perceptive Security
SOC/SIEM Consultancy

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), whic…
Published:
2 juni 2026 om 22:00:00
Alert date:
3 juni 2026 om 20:02:27
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
CVE-2026-36607 affects Mercusys AC12G (EU) V1 routers with firmware AC12G(EU)_V1_200909. The vulnerability allows unauthenticated brute-force attacks through the TDDP password change endpoint (code=10). Unlike the login endpoint (code=7), this endpoint lacks rate limiting protections. Attackers on the adjacent network can perform unlimited password attempts without triggering account lockout mechanisms. This represents a significant authentication bypass vulnerability in consumer networking equipment.
Technical details
Mitigation steps:
Affected products:
Mercusys AC12G
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-36607
https://github.com/Tymbark7372/MERCUSYS-AC12G/blob/master/advisories/CVE-2026-36607.md
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
