Executive brief
Tenda HG21 routers contain hardcoded administrative credentials in firmware version V4.0.0-260302, allowing unauthorized users to gain root-level access to the device. An attacker with network access to the router's management interface can use these credentials to take complete control of the device, compromise connected networks, and intercept or manipulate network traffic.
Technical details
This vulnerability stems from hardcoded administrative credentials embedded in the firmware of Tenda HG21 routers running version V4.0.0-260302. The Admin account contains fixed, publicly discoverable credentials that cannot be changed through normal configuration, allowing any networked attacker to authenticate and gain root-level access to the device. The attack requires only network reachability to the management interface and no user interaction or authentication bypass techniques. An attacker can leverage this access to modify firewall rules, install malware, perform man-in-the-middle attacks, or compromise the entire network behind the affected router. Patches or firmware updates addressing this issue have not been confirmed at this time.
Affected products
- Tenda HG21 V4.0.0-260302
Timeline
- 2026-08-31: disclosed