Hard-Coded Root Credential Vulnerability in Netis AC1200 Router
CVE-2026-36538

7.3HIGH

Key Information:

Vendor

Netis

Vendor
CVE Published:
27 May 2026

What is CVE-2026-36538?

The Netis AC1200 Router NC21 V4.0.1.4296 contains a critical vulnerability due to a hard-coded root credential stored in /etc/shadow.sample. The root account's password is set to 'root', which is easily guessable. This allows an unauthorized user who gains access to the device to authenticate as root, enabling them to take complete control of the router's operating system. Such exploitation could lead to further network compromises and data breaches, making it essential for users to seek updates or mitigations immediately.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.