Impact
The firmware for the Mercusys AC12G (EU) V1 transmits DDNS credentials over plain HTTP without encryption, using only Base64 encoding. This allows an attacker monitoring the network to capture user names and passwords for the DDNS service. Captured credentials could then be used to authenticate to the device or to the DDNS provider, potentially enabling unauthorized remote management or service compromise.
Affected Systems
Mercusys AC12G (EU) V1 running firmware AC12G(EU)_V1_200909.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. EPSS data is not available, but the absence of a CISA KEV listing suggests the vulnerability has not yet been widely exploited in the wild. The likely attack vector is passive network interception on an unsecured connection; an attacker would simply need to be able to observe HTTP traffic to the device. Because the issue is inherent to the firmware’s design and requires no special privilege, it could be exploited by any adversary who can view the device’s network traffic, indicating a moderate to high risk in environments where the router is exposed to untrusted networks.
OpenCVE Enrichment