SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-38577

CRITICAL · CVSS 9.8 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Tenda HG21 V4.0.0-260302 contains insecure hardcoded credentials in its Admin account, enabling attackers to gain root access to the device. This vulnerability poses a significant risk as it can lead to unauthorized control and manipulation of the affected systems. Organizations utilizing this model should prioritize remediation to prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-38577
Severity
CRITICAL
CVSS
9.8
EPSS
0.33%

Original NVD Description

Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.