A serious security flaw has been discovered in Tenda routers, with CERT/CC warning of a hidden backdoor that allows full administrative access without valid credentials. The vulnerability, tracked as CVE-2026-11405, affects multiple firmware versions of the Chinese networking equipment manufacturer and remains unpatched at the time of publication. It is one of the most worrying recent cases of hidden backdoors in networking equipment.

According to the CERT Coordination Center (CERT/CC), an attacker could exploit this vulnerability to bypass the password verification process and gain full administrative control without valid credentials. The backdoor is embedded in the firmware and is not visible through any administrative interface, making it particularly dangerous. The discovery was made by an anonymous researcher who reported the issue to the relevant authorities.
The issue affects a wide range of users, as Tenda routers are widely used in home and business environments around the world. The lack of a security update from the manufacturer leaves millions of devices exposed to potential attacks, while the nature of the backdoor suggests that it may have been there for a long time without being detected.
See also: Alibaba bans Claude Code due to alleged backdoor risk
The affected firmware versions are:
- US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD
- US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE
- US_AC10V1.0re_V15.03.06.46_multi_TDE01
- US_AC5V1.0RTL_V15.03.06.48_multi_TDE01
- US_AC6V2.0RTL_V15.03.06.51_multi_T
Tenda Router: How the hidden backdoor works – CVE-2026-11405
The backdoor is located within the “login()” function of the “/bin/httpd” web server binary. During normal execution flow, the method follows a standard authentication path using MD5 -based password verification . However, if this verification fails, an alternative code path is triggered that constitutes the backdoor itself.
Specifically, the alternative path calls the “GetValue(“sys.rzadmin.password”)” to retrieve an alternative password value from the device configuration. It then performs a direct plaintext between the password provided by the user and the value stored in the configuration. If these values match, the application grants administrator-level access (role=2) and creates a valid session with elevated privileges.
One particularly concerning aspect is that the associated username “rzadmin” is not verified. Therefore, any username will be accepted when combined with the backdoor password.

Tenda Router: Risks and Impacts of the Vulnerability
Successful exploitation of this username verification bypass allows full administrative access to the device's web interface, regardless of the account credentials . A malicious actor could perform unauthorized remote configuration modification, disable security features, or reconfigure the device, potentially leading to complete device takeover.
See also: Chinese Hackers Installed Hidden Backdoor in Linux Login Software for Nearly a Decade
In practical terms, this means that an attacker could redirect network traffic, monitor user data, install malware , or use the device as a launching pad for further attacks within the internal network. In corporate environments, such a breach could lead to sensitive data leaks or ransomware attacks. It is worth noting that automated scanners targeting known default IP can detect and exploit vulnerable devices without human intervention.
The vulnerability is part of a broader pattern of troubling findings in Chinese-made networking equipment. In recent years, several manufacturers have been the focus of investigations for built-in backdoors or weak security practices, raising questions about the hardware and software supply chain
Tenda Router: Protection and recommendations for users
Since no security update is available, CERT/CC recommends that users take other protective measures. First, it is recommended to disable remote management on the device to prevent access from the internet. Second, changing the default LAN IP address can reduce the risk of detection by automated scanners targeting known default IP ranges.
See also: FlutterShell Backdoor Spreads on macOS via Malicious Google and YouTube Ads
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, users should regularly monitor device logs for suspicious activity and consider replacing the device with alternative equipment from manufacturers with a proven security track record. Network segmentation is also a good practice to limit the potential damage in the event of a breach. Organizations using Tenda routers in business environments should immediately assess their exposure and proceed with replacement if feasible.
According to The Hacker News, the case once again highlights the importance of transparency from network equipment manufacturers and the need for stricter security controls on the firmware of the devices we use every day.
