> For the complete documentation index, see [llms.txt](https://threadpoolx.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://threadpoolx.gitbook.io/docs/cve/mercusys-ac12-v2-security-advisory/unprotected-physical-debug-interface-uart.md).

# Unprotected Physical Debug Interface (UART)

{% hint style="danger" %}
**High Severity Vulnerability** **CVE ID:** CVE-2026-78862

**Impact:** Unauthenticated Root Shell / Full System Compromise

**Attack Vector:** Physical / Local

**CVSS v4.0 Score:&#x20;**<mark style="color:$danger;">**8.6**</mark>

**CVSS Scoring :** CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
{% endhint %}

### Overview

An issue was identified in the **Mercusys AC12 V2** wireless router running firmware version `ac12v2-up_2020-09-03` and earlier. The device exposes an active Universal Asynchronous Receiver-Transmitter (UART) serial debug interface on its Printed Circuit Board (PCB). Connecting to this interface during the boot sequence grants unauthenticated root-level access to the underlying VxWorks shell (`tCmdTask`), enabling local attackers with physical access to execute arbitrary commands, modify configuration state, and completely compromise system integrity.

***

### Metadata & Classification

| Parameter              | Details                                                           |
| ---------------------- | ----------------------------------------------------------------- |
| **Vendor**             | Mercusys                                                          |
| **Product**            | AC12 Wireless Dual Band Router                                    |
| **Hardware Version**   | V2                                                                |
| **Firmware Version**   | `ac12v2-up_2020-09-03` (and prior)                                |
| **Vulnerability Type** | CWE-1299: Missing Protection for Debug or Diagnostic Interface    |
| **Secondary CWE**      | CWE-306: Missing Authentication for Critical Function             |
| **CVSS v4.0 Score**    | 8.6 (High)                                                        |
| **CVSS v4.0 Vector**   | `CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H` |
| **Discovered By**      | ThreadPoolX                                                       |

***

### Root Cause Analysis

During hardware security testing on the Mercusys AC12 V2 PCB, an active 4-pin UART serial interface was identified. The serial interface operates at standard 3.3V TTL logic levels and is fully functional in production units shipped to end users.

When the router boots up, the bootloader initializes the serial line and outputs system logs over UART at a baud rate of **115200 bps**. The bootloader configuration fails to restrict or password-protect serial console access. By interrupting or interacting with the boot sequence via serial interface input, the user is dropped directly into the **`tCmdTask` root execution shell** without any prompt for administrative authentication.

Because `tCmdTask` executes with full operating system privileges under VxWorks, an attacker on the console can read/write directly to system memory, invoke OS subroutines, inspect live configuration details, and modify device parameters.

***

### Lab Environment & Tooling

To replicate and verify this vulnerability, the following hardware and software tools are required:

#### Hardware Requirements

* **Target Device:** Mercusys AC12 V2 Router
* **Hardware Programmer:** USB-to-TTL Serial Adapter (3.3V Logic Level)
* **Interconnects:** Female-to-Female Jumper Wires / IC Test Hooks
* **Multimeter:** For identifying GND, TX, and RX pinouts

#### Software Requirements

* **Operating System:** Linux / macOS / Windows
* **Terminal Emulator:** `picocom`, `minicom`, or `screen`
* **Port Settings:** Baud rate `115200`, Data bits `8`, Parity `None`, Stop bits `1`, Flow Control `None`

***

### Proof of Concept (PoC)

{% hint style="info" %}
Ensure the USB-to-TTL adapter is strictly set to **3.3V TTL mode** before connecting to the router board to prevent electrical damage to the SoC.
{% endhint %}

1. **Disassembly:** Open the outer plastic casing of the Mercusys AC12 V2 router to access the internal PCB.
2. **Pinout Identification:** Locate the 4-pin UART header footprint near the main System-on-Chip (SoC). Verify the pinout mapping using a multimeter:

* **GND:** Ground reference
* **TX:** Transmit line (outputs boot logs)
* **RX:** Receive line (accepts command input)

3. **Serial Hookup:** Connect the USB-to-TTL serial adapter to the exposed header pins:

* Adapter **GND** $\rightarrow$ PCB **GND**
* Adapter **RX** $\rightarrow$ PCB **TX**
* Adapter **TX** $\rightarrow$ PCB **RX** *(Do **NOT** connect the VCC/5V line from the serial adapter).*

4. **Establish Terminal Session:** Connect the adapter to your workstation and open a serial communication terminal:

```bash
picocom -b 115200 /dev/ttyUSB0

```

5. **Trigger Root Shell:** Power cycle the router. As boot messages appear in the terminal, press **Enter** during the boot sequence window.
6. **Shell Access Verification:** The bootloader hands execution directly to the interactive root shell without requesting login credentials.

***

### Security Impact

* **Arbitrary Code Execution:** Direct access to kernel-level execution routines allows executing commands at maximum system privileges.
* **Credential Extraction:** Attackers can dump system RAM and unencrypted flash memory partitions containing Wi-Fi passwords, admin secrets, and ISP configuration parameters.
* **Persistent Tampering:** Physical access combined with debug interface access permits installing persistent backdoors or modifying operating system binaries directly on flash storage.

***

### Remediation Guidance

#### Recommendations for Manufacturers

1. **Disable UART Output in Production:** Strip or logically disable serial output in production firmware builds (`#undef DEBUG` or set bootloader silence flags).
2. **Enforce Authentication:** Implement password protection on the bootloader and terminal interfaces before dropping into shell mode.
3. **Hardware Depopulation:** Remove physical debug header pins and trace lines on production PCB revisions.

#### Recommendations for Network Administrators

1. Maintain strict physical access controls around network routing infrastructure.
2. Segment untrusted IoT hardware onto dedicated VLANs to restrict lateral movement in the event of physical device compromise.

***

### Timeline

* **February 17, 2026:** Vulnerability identified during hardware security analysis.
* **September 20, 2026:** CVE ID `CVE-2026-78862` officially assigned by MITRE.
* **September 22, 2026:** Public disclosure write-up published by ThreadPoolX.
