Hidden Tenda router firmware backdoor CVE-2026-11405 can give attackers administrator access

A hidden backdoor in several Tenda router firmware builds can let someone log into the device as an administrator if they know a separate undocumented password. CERT/CC says CVE-2026-11405 is in the /bin/httpd login() function, where failed normal authentication falls back to checking the plaintext password against the sys.rzadmin.password configuration value and then grants admin access regardless of username. Affected models include Tenda FH1201, W15E, AC10, AC5, and AC6 V2 on listed firmware versions, and no patch is available.
Why it matters: Home and small-office users could have their routers taken over, which can let attackers change network settings, weaken security, and potentially enable wider compromise of devices behind the router. If you use one of the affected models, disable remote web management now and reduce local exposure until Tenda releases a fix.

Sources

Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
Ionut Arghire 2026.07.09 99% relevant
This article is a direct report on the same Tenda firmware backdoor event, adding details from CERT/CC about the flawed login logic, affected device types beyond routers, lack of a vendor patch, and mitigations such as disabling remote web management.
Hidden backdoor in Tenda router firmware grants admin access
Bill Toulas 2026.07.07 100% relevant
This article appears to be the initial broad reporting on CVE-2026-11405, a distinct Tenda router backdoor disclosure with affected models, technical details, and mitigations, and it does not match an existing tracked story.
← Back to all stories