CVE-2026-78862
Received Received - Intake

Arbitrary Code Execution in Mercusys AC12 V2 via UART

Vulnerability report for CVE-2026-78862, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MITRE

Description

An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the UART serial interface on the printed circuit board (PCB)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a local code execution flaw in Mercusys AC12 V2 devices. It allows an attacker with physical access to the device via the UART serial interface on the PCB to run arbitrary commands.

Detection Guidance

This vulnerability requires physical access to the device's UART interface on the PCB. It cannot be detected remotely via network commands. To check for exposure, inspect the router's PCB for unpopulated UART pins (usually labeled TX, RX, GND) and ensure no debug headers are accessible. If found, the device is vulnerable.

Impact Analysis

An attacker could gain full control over the device, potentially intercepting network traffic, modifying settings, or using it as a foothold to attack other systems on the same network.

Compliance Impact

This vulnerability allows unauthenticated root-level access via an unprotected UART interface, enabling arbitrary code execution and full device compromise. Such unauthorized access could lead to unauthorized data access, modification, or exfiltration, violating GDPR and HIPAA requirements for data confidentiality and integrity.

Mitigation Strategies

Disable UART output in production firmware, enforce authentication for shell access, or remove debug headers if present. Implement physical access controls to prevent unauthorized disassembly. Network segmentation can limit potential damage if the device is compromised.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78862. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart