CERT Coordination Center (CERT/CC) identified an undocumented backdoor in Tenda router firmware. This vulnerability, tracked as CVE-2026-11405, enables attackers to gain administrative access to the devices without credentials. It affects several router models across multiple firmware versions.
The backdoor resides in the 'login()' function of the '/bin/httpd' web server binary. If standard MD5-based authentication fails, the system retrieves an alternate password from the device's configuration to proceed, granting administrative access when matched with any username.
The backdoor poses significant security threats by allowing unauthorized parties to modify device settings and potentially compromise the security of local networks. CERT/CC released an advisory highlighting five specific firmware versions affected. However, the full scope remains unknown due to Tenda's unresponsiveness.
Despite the severity of the flaw and efforts by CERT/CC to contact Tenda, the Shenzhen-based company has not issued any fixes. This lack of action leaves many users vulnerable to attacks that exploit this backdoor.
Affected firmware versions include:
- US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD
- US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE
- US_AC10V1.0re_V15.03.06.46_multi_TDE01
- US_AC5V1.0RTL_V15.03.06.48_multi_TDE01
- US_AC6V2.0RTL_V15.03.06.51_multi_T
The presence of such a vulnerability affects not only individual users but also could potentially compromise organizational networks where these devices are installed. Attackers could perform harmful actions like network scans, disabling security features, or rerouting web traffic.
Users and administrators with Tenda routers should be cautious and potentially disable remote management interfaces until a patch is available. Monitoring for unusual network activity is also advisable to mitigate risk.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Undocumented backdoors have been discovered in several Tenda router firmware versions, enabling unauthorized access. This vulnerability could allow attackers to control internal settings remotely, posing significant risks for users.
A security researcher found an unpatched backdoor in Tenda firmware, granting attackers administrative access. The backdoor, affecting routers and switches, allows for configuration changes and disabling security features, risking local network compromises.
A backdoor vulnerability in multiple Tenda router models allows attackers full admin control without credentials. Tenda has not provided a fix despite warnings from cybersecurity researchers, leaving users at risk.
Multiple Tenda firmware versions have an undocumented backdoor (CVE-2026-11405) that allows full administrative access without valid credentials, posing significant security risks for users. This vulnerability enables attackers to bypass password protections, modify device settings, and disable security features, potentially compromising local networks.
A hidden backdoor in Tenda router firmware enables attackers to gain unauthorized administrative access. This vulnerability, tracked as CVE-2026-11405, affects multiple router models and remains unfixed, posing serious security risks.
CERT/CC has uncovered an undocumented backdoor in multiple Tenda router firmware versions, allowing unauthorized administrative access. This vulnerability, tracked as CVE-2026-11405, poses significant security risks as attackers can bypass authentication and control devices remotely.