CVE-2026-36612
Description
Mercusys AC12G routers have a WPS 2.0 vulnerability allowing Wi-Fi credential recovery due to a predictable PIN and weak lockout policy.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Mercusys AC12G routers have a WPS 2.0 vulnerability allowing Wi-Fi credential recovery due to a predictable PIN and weak lockout policy.
Vulnerability
Mercusys AC12G (EU) V1 routers with firmware versions AC12G(EU)_V1_200909 and AC12G(EU)_V1_210128 enable WPS 2.0 by default. The implementation suffers from a weak lockout policy, allowing only 10 failed PIN attempts before a 60-second lockout, and the AP PIN can be deterministically derived from the BSSID MAC address [1].
Exploitation
An attacker needs network access and must wait for the user to activate WPS PIN mode via the web UI or a physical button. Once WPS PIN mode is active, the attacker can predict the AP PIN using the BSSID MAC address and attempt to recover the Wi-Fi credentials within a single WPS PIN exchange attempt, bypassing the weak lockout policy [1].
Impact
Successful exploitation allows an attacker to recover Wi-Fi credentials, granting them full access to the local area network and all connected devices. This could lead to further compromise of networked systems [1].
Mitigation
The affected products are end-of-life, and no fix is planned. Users are advised to disable WPS by default on their routers if possible. Increasing the lockout duration and the number of failed attempts are recommended security practices, but are not available as a firmware update for these devices [1].
AI Insight generated on Jun 3, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- Mercusys AC12G Router: 15 Vulnerabilities Disclosed on June 3, 2026Vypr Intelligence · Jun 3, 2026