Impact
The Mercusys AC12G router exposes a password‑change API (endpoint code 10) that is unsecured and lacks any form of rate limiting. Because the endpoint accepts requests without authentication, an attacker can continuously submit password guesses until the correct value is discovered. This permits an unauthenticated user to obtain full administrative credentials, enabling complete control of the device, potential compromise of the local network, and the ability to redirect or disrupt network traffic. The flaw represents a weakness in authentication controls and input validation as specified by CWE‑307 and CWE‑400.
Affected Systems
The vulnerability affects Mercusys AC12G (EU) V1 routers running firmware version AC12G(EU)_V1_200909. No other versions or products are listed as impacted.
Risk and Exploitability
The CVE does not provide a CVSS score or EPSS value, and it is not listed in CISA’s KEV catalog. Nevertheless, the lack of rate limiting combined with the ability to reach the endpoint from an adjacent network creates a high likelihood of exploitation if an attacker gains local network access. Because an attacker can attempt unlimited password guesses, the probability of a successful credential compromise is substantial, elevating the overall risk to organizational network security.
OpenCVE Enrichment