logo

CERT Warns of Unpatched Tenda Firmware Backdoor Allowing Admin Access

ID: 72955721-1ab9-56b0-8052-daa30f129034

STIX ID: report--72955721-1ab9-56b0-8052-daa30f129034

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-07-09

Date Updated: 2026-07-20

Author: Ashish Khaitan

...
...

CERT/CC disclosed two unpatched security issues: CVE-2026-11405, an undocumented backdoor in multiple Tenda networking devices allowing attackers who know the configured backdoor password to bypass authentication and gain administrative access; and CVE-2026-13753, a missing authorization flaw in HP DeskJet 2800 series printers that returns sensitive administrative and Wi‑Fi credentials via unauthenticated API endpoints. CERT advises immediate mitigations (disable remote web management, change default LAN IP) while no patches are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.