Undefined · Undefined · CVE-2026-36606
**Name of the Vulnerable Software and Affected Versions**
Mercusys AC12G (EU) V1 version AC12G(EU) V1 200909
**Description**
Configuration backups are encrypted using a hardcoded DES key with single DES in ECB (Electronic Codebook) mode, which is a basic encryption mode that does not use an initialization vector. An attacker with access to a backup file can decrypt it to recover sensitive stored credentials, such as the administrator password, WiFi PSK, and DDNS credentials.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.