← All stories
● Covered by 6 sources · 6 reportsMedium impact

CERT/CC Reports Hidden Backdoor in Tenda Router Firmware Allowing Admin Access

🔄 Updated 84d ago — new reporting from ZDNET
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CERT/CC uncovered a Tenda router backdoor, tracked as CVE-2026-11405.
  • The vulnerability affects several firmware versions, allowing admin access.
  • Attackers can bypass passwords through a secret mechanism in '/bin/httpd'.
  • Tenda has not responded to notifications about the security issue.
  • Affected routers' authentication can be bypassed with an alternate password.

Overview of the Vulnerability

CERT Coordination Center (CERT/CC) identified an undocumented backdoor in Tenda router firmware. This vulnerability, tracked as CVE-2026-11405, enables attackers to gain administrative access to the devices without credentials. It affects several router models across multiple firmware versions.

The backdoor resides in the 'login()' function of the '/bin/httpd' web server binary. If standard MD5-based authentication fails, the system retrieves an alternate password from the device's configuration to proceed, granting administrative access when matched with any username.

Unpatched Security Risks

The backdoor poses significant security threats by allowing unauthorized parties to modify device settings and potentially compromise the security of local networks. CERT/CC released an advisory highlighting five specific firmware versions affected. However, the full scope remains unknown due to Tenda's unresponsiveness.

Despite the severity of the flaw and efforts by CERT/CC to contact Tenda, the Shenzhen-based company has not issued any fixes. This lack of action leaves many users vulnerable to attacks that exploit this backdoor.

Affected firmware versions include:

- US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD

- US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE

- US_AC10V1.0re_V15.03.06.46_multi_TDE01

- US_AC5V1.0RTL_V15.03.06.48_multi_TDE01

- US_AC6V2.0RTL_V15.03.06.51_multi_T

Potential Impact and Recommendations

The presence of such a vulnerability affects not only individual users but also could potentially compromise organizational networks where these devices are installed. Attackers could perform harmful actions like network scans, disabling security features, or rerouting web traffic.

Users and administrators with Tenda routers should be cautious and potentially disable remote management interfaces until a patch is available. Monitoring for unusual network activity is also advisable to mitigate risk.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Undocumented backdoors have been discovered in several Tenda router firmware versions, enabling unauthorized access. This vulnerability could allow attackers to control internal settings remotely, posing significant risks for users.

A security researcher found an unpatched backdoor in Tenda firmware, granting attackers administrative access. The backdoor, affecting routers and switches, allows for configuration changes and disabling security features, risking local network compromises.

A backdoor vulnerability in multiple Tenda router models allows attackers full admin control without credentials. Tenda has not provided a fix despite warnings from cybersecurity researchers, leaving users at risk.

Multiple Tenda firmware versions have an undocumented backdoor (CVE-2026-11405) that allows full administrative access without valid credentials, posing significant security risks for users. This vulnerability enables attackers to bypass password protections, modify device settings, and disable security features, potentially compromising local networks.

A hidden backdoor in Tenda router firmware enables attackers to gain unauthorized administrative access. This vulnerability, tracked as CVE-2026-11405, affects multiple router models and remains unfixed, posing serious security risks.

CERT/CC has uncovered an undocumented backdoor in multiple Tenda router firmware versions, allowing unauthorized administrative access. This vulnerability, tracked as CVE-2026-11405, poses significant security risks as attackers can bypass authentication and control devices remotely.