CVE-2026-78860
Received Received - Intake

Mercusys AC12 V2 Plaintext Credential Storage Arbitrary Code Execution

Vulnerability report for CVE-2026-78860, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MITRE

Description

An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78860 is a high-severity vulnerability affecting the Mercusys AC12 V2 wireless router. It involves missing firmware encryption and a lack of secure boot mechanisms, allowing physical or local attackers to exploit the device through unprotected SPI flash storage.

Detection Guidance

This vulnerability requires physical access to the device and cannot be detected remotely. Check if your Mercusys AC12 V2 runs firmware version ac12v2-up_2020-09-03 or earlier. Use a CH341A SPI flash programmer with a SOP8 test clip to inspect the SPI flash memory for unencrypted data or unauthorized modifications.

Impact Analysis

An attacker with physical access can dump flash memory to extract plaintext credentials, flash malicious firmware for persistent code execution, modify credentials, install backdoors, or brick the device by overwriting the bootloader.

Compliance Impact

The vulnerability allows physical attackers to extract plaintext credentials and modify firmware, which could lead to unauthorized access to sensitive data. This may violate GDPR's data protection requirements for secure storage and HIPAA's safeguards for protected health information if the device processes such data.

Mitigation Strategies

Immediately update the firmware to the latest version if available. Physically secure the router in a restricted area to prevent unauthorized access. Consider replacing the device if no secure firmware update is provided, as the lack of encryption and secure boot cannot be fully mitigated without manufacturer intervention.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78860. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart