> For the complete documentation index, see [llms.txt](https://threadpoolx.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://threadpoolx.gitbook.io/docs/cve/mercusys-ac12-v2-security-advisory/hardcoded-private-key.md).

# Hardcoded Private Key

{% hint style="danger" %}
**High Severity Vulnerability** **CVE ID:** CVE-2026-78861

**Impact:** Information Disclosure / Cryptographic Bypass / Privilege Escalation

**Attack Vector:** Local
{% endhint %}

### Overview

An issue was identified in the **Mercusys AC12 V2** wireless router running firmware version `ac12v2-up_2020-09-03` and earlier. The device firmware contains a hardcoded 512-bit RSA Private Key (`priv-key.pem`) located within the web server's resource partition. Because this static cryptographic key is identical and shared across all devices running this firmware version, a local attacker can extract the key from the filesystem and compromise cryptographic protections, leading to arbitrary code execution, unauthorized access, or the decryption of administrative communications.

***

### Metadata & Classification

| **Parameter**      | **Details**                                                                                                 |
| ------------------ | ----------------------------------------------------------------------------------------------------------- |
| Vendor             | Mercusys                                                                                                    |
| Product            | AC12 Wireless Dual Band Router                                                                              |
| Hardware Version   | V2                                                                                                          |
| Firmware Version   | `ac12v2-up_2020-09-03` (and prior)                                                                          |
| Vulnerability Type | <p>CWE-798: Use of Hard-coded Credentials</p><p><br></p><p>CWE-321: Use of Hard-coded Cryptographic Key</p> |
| CVSS v4.0 Score    | 8.2 (High)                                                                                                  |
| CVSS v4.0 Vector   | `CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N`                                           |
| Discovered By      | ThreadPoolX                                                                                                 |

***

### Root Cause Analysis

During static analysis of the official Mercusys AC12 V2 firmware, a globally shared 512-bit RSA private key was discovered embedded directly into the router's file system. The file, named `priv-key.pem`, is used by the router's internal services (such as the local web server) to handle encrypted communications or authentication tokens.

Embedding a static private key directly into the firmware image violates basic cryptographic security principles. Because the exact same firmware binary is flashed onto thousands of devices during manufacturing, every single AC12 V2 unit globally shares this exact same RSA private key. If an attacker extracts this key from a single firmware file, they possess the private key for every other router of this model, enabling them to decrypt intercepted traffic, forge administrative session tokens, or bypass cryptographic signature checks. Furthermore, a 512-bit RSA key length is cryptographically weak and considered obsolete by modern standards.

***

### Lab Environment & Tooling

To replicate and verify this vulnerability, the following software environment and tools are required:

#### Software Requirements

* **Operating System:** Kali Linux (or any standard Linux distribution)
* **Extraction Tools:** `binwalk` (for unpacking firmware filesystems)
* **Analysis Tools:** `grep`, `strings`
* **Cryptographic Tools:** `openssl` (for validating the RSA key structure)

***

### Proof of Concept (PoC)

{% hint style="info" %}
This extraction can be performed entirely offline using the publicly available firmware update binary hosted on the vendor's official support website, requiring no physical interaction with the router itself.
{% endhint %}

1. **Acquire Firmware:** Download the official firmware binary `ac12v2-up_2020-09-03.bin` from the manufacturer's website or extract it directly from the device's SPI flash memory.
2. **Extract Filesystem:** Use `binwalk` to carve and extract the embedded Linux filesystem from the raw binary image:

```bash
binwalk -e ac12v2-up_2020-09-03.bin
```

3. **Locate the Private Key:** Navigate into the extracted filesystem directory (typically named `_ac12v2-up_2020-09-03.bin.extracted`) and search for standard RSA key headers:

```bash
grep -rnw . -e '-----BEGIN RSA PRIVATE KEY-----'
```

4. **Identify the Key File:** The search will reveal the location of the key file (e.g., `web/resources/priv-key.pem`).
5. **Validate the Key:** Pass the extracted `.pem` file to OpenSSL to verify that it is a valid, unencrypted private key and to expose its 512-bit length:

```bash
openssl rsa -in priv-key.pem -text -noout
```

**Expected OpenSSL Output:**

```
Private-Key: (512 bit, 2 primes)
modulus:
    00:b2:3a:... (hex dump)
publicExponent: 65537 (0x10001)
privateExponent:
    ...

```

***

### Security Impact

* **Session Hijacking & MitM:** An attacker on the local network can use the shared private key to perform Man-in-the-Middle (MitM) attacks, passively decrypting HTTPS/TLS traffic between a legitimate administrator and the router's web interface.
* **Authentication Forgery:** If the key is used to sign cookies or authentication tokens, an attacker can forge valid administrative sessions to execute arbitrary code or change device settings.
* **Weak Cryptography:** The 512-bit key length is inherently insecure and can be factored by modern hardware in a matter of hours, compounding the severity of the hardcoded key.

***

### Remediation Guidance

#### Recommendations for Manufacturers

1. **Dynamic Key Generation:** Remove static `.pem` files from the global firmware image. Instead, program the firmware to dynamically generate a unique, cryptographically secure RSA or ECDSA key pair during the device's first boot sequence.
2. **Increase Key Strength:** Ensure all generated RSA keys are at least 2048-bit, or transition to modern Elliptic Curve Cryptography (e.g., secp256r1 / NIST P-256).
3. **Secure Storage:** Store dynamically generated keys in a protected NVRAM partition or hardware-backed secure enclave, ensuring they cannot be easily exported if the filesystem is dumped.

#### Recommendations for Network Administrators

1. Do not expose the router's management interface to untrusted networks (e.g., WAN/Internet).
2. Assume local management traffic is susceptible to interception and avoid logging into the router from untrusted or public Wi-Fi access points.

***

### Timeline

* **February 17, 2026:** Vulnerability identified during firmware static analysis.
* **September 20, 2026:** CVE ID `CVE-2026-78861` officially assigned by MITRE.
* **September 22, 2026:** Public disclosure write-up published by ThreadPoolX.
