CVE-2026-36612: n/a
The Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 has WPS 2. 0 enabled by default and implements a weak lockout policy that only blocks attempts for 60 seconds after 10 failed tries. This configuration could allow an attacker to repeatedly attempt WPS PIN authentication with limited delay, potentially increasing the risk of unauthorized access. No official patch or remediation guidance is currently available. No known exploits are reported in the wild. The severity is assessed as medium given the weak lockout but lack of confirmed exploitation or detailed impact data.
AI Analysis
Technical Summary
This vulnerability concerns the Mercusys AC12G (EU) V1 router running firmware AC12G(EU)_V1_200909, which enables Wi-Fi Protected Setup (WPS) version 2.0 by default. The device enforces a lockout policy after 10 failed WPS attempts, but the lockout duration is only 60 seconds, which is considered weak. This weak lockout policy may allow attackers to perform repeated WPS PIN attempts with minimal delay, potentially facilitating brute-force attacks against the WPS PIN. No CVSS score or vendor remediation information is available, and no exploits have been reported in the wild.
Potential Impact
The weak lockout policy on WPS 2.0 allows an attacker to attempt multiple WPS PIN authentications with only a short 60-second lockout after 10 failed attempts. This could increase the likelihood of successful brute-force attacks against the WPS PIN, potentially leading to unauthorized network access. However, no known exploits have been reported, and the actual impact depends on attacker capabilities and network configurations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider disabling WPS on the affected device if possible to mitigate the risk associated with the weak lockout policy.
CVE-2026-36612: n/a
Description
The Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 has WPS 2. 0 enabled by default and implements a weak lockout policy that only blocks attempts for 60 seconds after 10 failed tries. This configuration could allow an attacker to repeatedly attempt WPS PIN authentication with limited delay, potentially increasing the risk of unauthorized access. No official patch or remediation guidance is currently available. No known exploits are reported in the wild. The severity is assessed as medium given the weak lockout but lack of confirmed exploitation or detailed impact data.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability concerns the Mercusys AC12G (EU) V1 router running firmware AC12G(EU)_V1_200909, which enables Wi-Fi Protected Setup (WPS) version 2.0 by default. The device enforces a lockout policy after 10 failed WPS attempts, but the lockout duration is only 60 seconds, which is considered weak. This weak lockout policy may allow attackers to perform repeated WPS PIN attempts with minimal delay, potentially facilitating brute-force attacks against the WPS PIN. No CVSS score or vendor remediation information is available, and no exploits have been reported in the wild.
Potential Impact
The weak lockout policy on WPS 2.0 allows an attacker to attempt multiple WPS PIN authentications with only a short 60-second lockout after 10 failed attempts. This could increase the likelihood of successful brute-force attacks against the WPS PIN, potentially leading to unauthorized network access. However, no known exploits have been reported, and the actual impact depends on attacker capabilities and network configurations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, consider disabling WPS on the affected device if possible to mitigate the risk associated with the weak lockout policy.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-04-06T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a20657ce29bf47b50d4100e
Added to database: 6/3/2026, 5:33:48 PM
Last enriched: 6/3/2026, 5:49:02 PM
Last updated: 6/3/2026, 6:38:25 PM
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.