logo

Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available

ID: 41aaa4ed-c8dd-5197-8280-be5da0b50c5c

STIX ID: report--41aaa4ed-c8dd-5197-8280-be5da0b50c5c

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-07-07

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

CERT/CC has published an advisory for CVE-2026-11405: multiple Tenda router firmware versions (FH1201, W15E, AC10, AC5, AC6) contain an undocumented authentication backdoor that checks a hidden sys.rzadmin.password value in the webserver binary (/bin/httpd) and grants role=2 (admin) without validating the username or configured credentials; the flaw is baked into firmware, currently unpatched with no vendor response, and CERT/CC recommends disabling remote management and isolating affected devices until a firmware fix is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.