Impact
The Mercusys AC12G router exposes a password‑change API (endpoint code 10) that is unsecured and lacks any form of rate limiting. Because the endpoint accepts requests without authentication, an attacker can continuously submit password guesses until the correct value is discovered. This permits an unauthenticated user to obtain full administrative credentials, enabling complete control of the device, potential compromise of the local network, and the ability to redirect or disrupt network traffic. The flaw represents a weakness in authentication controls and input validation as specified by CWE-307.
Affected Systems
The vulnerability affects Mercusys AC12G (EU) V1 routers running firmware version AC12G(EU)_V1_200909. No other versions or products are listed as impacted.
Risk and Exploitability
The CVE provides a CVSS score of 8.8 but no EPSS value, and it is not listed in CISA’s KEV catalog. The high severity rating, combined with the lack of rate limiting and unrestricted access from adjacent networks, creates a high likelihood of exploitation if an attacker gains local network access. Because an attacker can attempt unlimited password guesses, the probability of a successful credential compromise is substantial, elevating the overall risk to organizational network security.
OpenCVE Enrichment