Impact
The vulnerability stems from an insecure, hardcoded administration account that allows an attacker to authenticate with a known password, granting full root privileges. This effectively compromises the confidentiality, integrity, and availability of the device, enabling an attacker to modify configuration, install malware, or disrupt network traffic. The weakness is an instance of improper handling of credentials, which is serious when the affected system is a network gateway.
Affected Systems
The flaw is present in the Tenda HG21 router running firmware version 4.0.0-260302. No other affected versions or products are listed, and the vendor has not issued an official advisory or patch as of the latest information.
Risk and Exploitability
No CVSS or EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation through the device’s web interface, assuming inbound network access or that the router is exposed to the internet. While exploitation details are sparse, the presence of deterministic credentials would allow an attacker to compromise the router with minimal effort if exposure exists. Defenders should assume a high likelihood of exploitation in exposed environments and a lower probability in strictly isolated networks.
OpenCVE Enrichment