Description
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
Published: 2026-08-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Root access through hardcoded credentials
Action: Immediate Update
AI Analysis

Impact

The vulnerability stems from an insecure, hardcoded administration account that allows an attacker to authenticate with a known password, granting full root privileges. This effectively compromises the confidentiality, integrity, and availability of the device, enabling an attacker to modify configuration, install malware, or disrupt network traffic. The weakness is an instance of improper handling of credentials, which is serious when the affected system is a network gateway.

Affected Systems

The flaw is present in the Tenda HG21 router running firmware version 4.0.0-260302. No other affected versions or products are listed, and the vendor has not issued an official advisory or patch as of the latest information.

Risk and Exploitability

The CVSS score is 9.8, and the EPSS score is less than 1%; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation through the device’s web interface, assuming inbound network access or that the router is exposed to the internet. While exploitation details are sparse, the presence of deterministic credentials would allow an attacker to compromise the router with minimal effort if exposure exists. Defenders should assume a high likelihood of exploitation in exposed environments and a lower probability in strictly isolated networks.

Generated by OpenCVE AI on September 2, 2026 at 04:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tenda firmware that removes or secures the hardcoded admin credentials
  • If an update is unavailable, change the default admin password immediately or disable the admin interface
  • Limit administrative interface access to trusted internal networks or block external ports with a firewall
  • Monitor logs for unauthorized login attempts

Generated by OpenCVE AI on September 2, 2026 at 04:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Hardcoded Admin Credentials Grant Root Access in Tenda HG21 Router Firmware

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda hg21
Vendors & Products Tenda
Tenda hg21

Mon, 31 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Hardcoded Admin Credentials Grant Root Access in Tenda HG21 Router Firmware
Weaknesses CWE-798

Mon, 31 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-01T14:40:41.208Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38577

cve-icon Vulnrichment

Updated: 2026-09-01T14:40:27.832Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T21:17:07.930

Modified: 2026-09-01T21:00:36.830

Link: CVE-2026-38577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:30:04Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials