Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available
ID: 41aaa4ed-c8dd-5197-8280-be5da0b50c5c
STIX ID: report--41aaa4ed-c8dd-5197-8280-be5da0b50c5c
Feed Name: Security Affairs
CERT/CC has published an advisory for CVE-2026-11405: multiple Tenda router firmware versions (FH1201, W15E, AC10, AC5, AC6) contain an undocumented authentication backdoor that checks a hidden sys.rzadmin.password value in the webserver binary (/bin/httpd) and grants role=2 (admin) without validating the username or configured credentials; the flaw is baked into firmware, currently unpatched with no vendor response, and CERT/CC recommends disabling remote management and isolating affected devices until a firmware fix is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
