NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-36610
Summary

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, allowing man-in-the-middle interception of DDNS service credentials.

Publication Date June 4, 2026, 3:16 a.m.
Registration Date June 4, 2026, 4:16 a.m.
Last Update June 4, 2026, 3:16 a.m.
Related information, measures and tools
Common Vulnerabilities List