External risk intelligence

Tenda HG21 V4.0.0-260302 Hardcoded Admin Credentials Allow Root Access

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-38577

The vulnerability affects a Tenda router, which is a network edge device. Such devices are commonly deployed as internet-facing gateways, and the administrative interface is frequently exposed to the network, making it reachable from the internet in many standard home or small office deployment scenarios.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in Tenda routers, specifically concerning the administrator account. This vulnerability could allow unauthorized individuals to gain complete control over the device, potentially impacting network integrity and user data. The primary concern is to confirm if this type of device is in use and if it is exposed to external networks.

  • Hardcoded credentials grant root access.
  • Network edge devices are commonly internet-exposed.
  • Confirm usage and exposure of affected devices.

Attack Path

How an attacker could exploit the issue

An attacker can leverage hardcoded administrative credentials within the Tenda HG21 router to gain unauthorized root access. This vulnerability is accessible over the network, meaning an attacker could potentially exploit it remotely without needing any prior access or authentication. Successful exploitation would grant the attacker full control over the device.

  • Network exposure required.
  • Insecure hardcoded credentials trigger.
  • Full root access and device control.

Live Threat

Current exploitation, exposure, and threat context

Insecure hardcoded credentials in the Admin account of Tenda HG21 routers could allow an unauthenticated attacker to gain root access to the device. This could potentially affect the confidentiality, integrity, and availability of the device and any data it processes or transmits.

  • Root access to the router.
  • Unauthenticated network access.
  • Device compromise and data interception.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects network edge devices, specifically Tenda routers. Infrastructure or network teams are likely responsible for managing these devices. The first step is to identify all deployed instances, confirm their network exposure, and assess their business criticality to prioritize remediation.

  • Network infrastructure teams own the issue.
  • Verify router exposure and criticality.
  • Plan maintenance for remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Tenda HG21 V4.0.0-260302 router?

The Tenda HG21 is a networking device typically used as a gateway or router to connect homes or small offices to the internet. This specific version, V4.0.0-260302, serves as the central hub for managing local network traffic and security. Because it handles internet connectivity, it acts as the perimeter between a private local network and the public internet.

What does CWE-798 mean for this vulnerability?

CWE-798 refers to the use of hardcoded credentials. In the context of CVE-2026-38577, this means the device's administrative account uses a fixed, unchangeable password built into the software. This is a significant security weakness because it bypasses standard authentication, allowing anyone who knows or discovers this password to log in as an administrator without needing to legitimately set or manage a password.

How can an attacker trigger this root access bug?

An attacker triggers this vulnerability by attempting to log in to the device's administrative interface using the hardcoded credentials. This process does not require existing access to the internal network; however, the device must be reachable over the network to accept the login request. Simply having the device powered on or using its local Wi-Fi features is not the trigger itself; the vulnerability is only invoked by sending a connection request to the admin interface.

Is my Tenda HG21 device at risk?

Your device is at higher risk if it is configured to be internet-facing. According to Halo Surface Signal, these routers are commonly deployed as network edge devices, meaning they are frequently reachable from the public internet. If the administrative interface is accessible from outside your local network, the risk of unauthorized access via these hardcoded credentials increases significantly compared to devices kept strictly internal.

How should I respond to CVE-2026-38577?

Start by identifying all instances of the Tenda HG21 V4.0.0-260302 within your environment. Once identified, verify whether the administrative interface is exposed to the internet. If it is, restrict network access to this interface immediately to prevent remote reachability. Finally, consult the manufacturer for official updates or configuration guidance to mitigate the risks associated with the hardcoded credentials.