Hidden backdoor in Tenda router firmware grants admin access
ID: a89d0f8f-79a7-5e45-86fc-38f157f85a76
STIX ID: report--a89d0f8f-79a7-5e45-86fc-38f157f85a76
Feed Name: Bleeping Computer
Threat Score
A hidden authentication backdoor (CVE-2026-11405) in multiple Tenda router firmware versions allows an attacker to bypass normal MD5-based auth by supplying a plaintext backdoor password stored in 'sys.rzadmin.password', granting full administrative web-panel access; CERT/CC reports no patch, advises disabling remote web management and reducing LAN exposure, and warns the flaw is likely to be targeted by botnets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
