Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to the trivially weak value root, allowing an attacker with access to the device to authenticate as root and gain full control of the underlying operating system.
References
Configurations
No configuration.
History
28 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/sir3ns/cve-disclosure/blob/main/CVE-2026-36538/readme.md - | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
| CWE | CWE-798 |
27 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 14:16
Updated : 2026-05-28 14:16
NVD link : CVE-2026-36538
Mitre link : CVE-2026-36538
CVE.ORG link : CVE-2026-36538
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials
