Tenda Router Firmware: Hidden Admin Backdoor Alert (2026)

The recent discovery of a hidden admin backdoor in Tenda router firmware by the CERT Coordination Center (CERT/CC) has raised serious concerns about the security of network devices. This vulnerability, tracked as CVE-2026-11405, allows attackers to bypass password verification and gain full administrative control over affected routers. What makes this issue particularly insidious is the fact that the backdoor is not documented and is not visible through any administrative interface, making it difficult for users to detect and mitigate. The backdoor functionality is embedded within the login() function of the /bin/httpd web server binary. While the initial authentication process appears normal, using MD5-based password verification, it activates an alternate code path if the authentication fails. This alternate path involves fetching an alternate password value from the device configuration and performing a direct plaintext comparison. If the user-supplied password matches the stored value, the application grants admin-level access and creates a valid session with elevated privileges. The CERT/CC highlights that the associated rzadmin username is not validated, meaning any provided username will succeed when paired with the backdoor password. This vulnerability has far-reaching implications, as it enables attackers to make unauthorized remote modifications to settings, disable security features, or reconfigure the device, potentially leading to a complete device takeover. The impact is significant, as it affects multiple versions of Tenda firmware, including USFH1201V1.0BRV1.2.0.14(408)ENTD, USW15EV1.0brV15.11.0.5(10681567841)ENTDE, USAC10V1.0reV15.03.06.46multiTDE01, USAC5V1.0RTLV15.03.06.48multiTDE01, and USAC6V2.0RTLV15.03.06.51multiT. As of the article's publication, the vulnerability remains unpatched, and Tenda has not yet responded to requests for comment. Users are urged to take immediate action to protect their networks. The CERT/CC recommends disabling remote management on the device and changing the default LAN IP address to prevent unauthorized access and reduce the risk of automated scanners discovering the device. This incident underscores the importance of vigilance in network security. It serves as a stark reminder that even seemingly secure devices can have hidden vulnerabilities. As a result, users must remain proactive in implementing security measures and staying informed about potential threats. The discovery of this backdoor also highlights the need for better transparency and documentation in firmware development. Manufacturers should prioritize security by design, ensuring that their products are robust and resistant to such attacks. In conclusion, the hidden admin backdoor in Tenda router firmware is a critical issue that demands immediate attention. Users should take preventive measures, and manufacturers must prioritize security to protect their customers' networks from potential threats.

Tenda Router Firmware: Hidden Admin Backdoor Alert (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Dr. Pierre Goyette

Last Updated:

Views: 5883

Rating: 5 / 5 (70 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Dr. Pierre Goyette

Birthday: 1998-01-29

Address: Apt. 611 3357 Yong Plain, West Audra, IL 70053

Phone: +5819954278378

Job: Construction Director

Hobby: Embroidery, Creative writing, Shopping, Driving, Stand-up comedy, Coffee roasting, Scrapbooking

Introduction: My name is Dr. Pierre Goyette, I am a enchanting, powerful, jolly, rich, graceful, colorful, zany person who loves writing and wants to share my knowledge and understanding with you.