ZeroHour

CVE-2026-38577

Hardcoded Admin Credentials Grant Root Access in Tenda HG21

CVSS 3.1
9.8 critical
EPSS
<1%p26
Published
()
Modified
AI analysis

Tenda HG21 devices running firmware V4.0.0-260302 ship with hard-coded credentials embedded in the built-in Admin account (CWE-798). Because these credentials are fixed in the firmware and cannot be changed by the user, any attacker who can reach the device's network-facing management interface can log in with the embedded credentials without cracking a password. A successful login grants the attacker root access to the device, meaning full administrative control, which is why the issue carries a critical CVSS 9.8 rating reflecting potentially complete loss of confidentiality, integrity, and availability. Anyone operating a Tenda HG21 on firmware V4.0.0-260302 is affected; the available data does not specify whether other firmware versions are also impacted. As of now no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only about a 0.3% probability of exploitation in the next 30 days.

What to do: Inventory your estate for Tenda HG21 devices and check whether they run firmware V4.0.0-260302, then apply Tenda's fixed firmware as soon as one is released (the available data does not name a fixed version). In the meantime, restrict exposure of the management interface by disabling WAN-side administration and limiting admin access to trusted networks, and monitor Tenda advisories, since hard-coded credentials can only be remediated through a firmware update.

Affected
Tenda HG21V4.0.0-260302 (only this version is specified in the available data; other versions unconfirmed)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.

Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.