Summary
CVE-2026-38577 is a critical vulnerability (CWE-798: Use of Hard-coded Credentials) affecting the Tenda HG21 router running firmware V4.0.0-260302. The Admin account on affected devices uses insecure hardcoded credentials, allowing an unauthenticated remote attacker to gain root-level access to the device. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: The Admin account on affected firmware relies on hardcoded (embedded, non-configurable) credentials rather than credentials set or rotated by the device owner.
- Trigger conditions: No prior authentication or user interaction is required; an attacker only needs network access to the device’s management interface.
- Attack vector: Network (remote), with low attack complexity and no privileges required.
- Impact: Successful exploitation grants root access to the device, resulting in complete loss of confidentiality, integrity, and availability of the device and any traffic/network it controls.
Affected software
- Tenda HG21, firmware version V4.0.0-260302
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: No official Tenda patch or advisory has been identified for this CVE at the time of writing. Check the Tenda support site for a firmware update superseding V4.0.0-260302 and apply it as soon as it is available.
- If no patch is available:
- Remove the device’s administrative/management interface from direct internet exposure; restrict access to trusted internal networks or VPN only.
- Place the device behind a firewall that blocks inbound access to management ports/services from the WAN.
- Monitor for unexpected administrative logins or configuration changes.
- Where feasible, replace or isolate affected devices until a vendor fix is confirmed.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Tenda Web Master - Raw response body: an anchor element with a
brandclass andtitle="Tenda"

