CVE-2026-38577: Tenda HG21 vulnerability
Published Aug 31, 2026
·Updated
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.
Affected Software
1 affected component
Tenda HG21=4.0.0-260302
Event History
Aug 31, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is described as hardcoded credentials in the device's Admin account. An attacker would need to be able to authenticate to an affected device using those credentials.
2
What is the impact of successful exploitation?
Successful use of the hardcoded Admin account credentials allows an attacker to gain root access.