Description
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
Published: 2026-08-31
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from an insecure, hardcoded administration account that allows an attacker to authenticate with a known password, granting full root privileges. This effectively compromises the confidentiality, integrity, and availability of the device, enabling an attacker to modify configuration, install malware, or disrupt network traffic. The weakness is an instance of improper handling of credentials, which is serious when the affected system is a network gateway.

Affected Systems

The flaw is present in the Tenda HG21 router running firmware version 4.0.0-260302. No other affected versions or products are listed, and the vendor has not issued an official advisory or patch as of the latest information.

Risk and Exploitability

No CVSS or EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation through the device’s web interface, assuming inbound network access or that the router is exposed to the internet. While exploitation details are sparse, the presence of deterministic credentials would allow an attacker to compromise the router with minimal effort if exposure exists. Defenders should assume a high likelihood of exploitation in exposed environments and a lower probability in strictly isolated networks.

Generated by OpenCVE AI on August 31, 2026 at 21:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tenda firmware that removes or secures the hardcoded admin credentials
  • If an update is unavailable, change the default admin password immediately or disable the admin interface
  • Limit administrative interface access to trusted internal networks or block external ports with a firewall
  • Monitor logs for unauthorized login attempts

Generated by OpenCVE AI on August 31, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Hardcoded Admin Credentials Grant Root Access in Tenda HG21 Router Firmware
Weaknesses CWE-798

Mon, 31 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T20:19:18.408Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:07.930

Modified: 2026-08-31T21:17:07.930

Link: CVE-2026-38577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:00:06Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials