HomeSecurityTenda Router: Hidden backdoor in router firmware

Tenda Router: Hidden backdoor in router firmware

A serious security flaw has been discovered in Tenda routers, with CERT/CC warning of a hidden backdoor that allows full administrative access without valid credentials. The vulnerability, tracked as CVE-2026-11405, affects multiple firmware versions of the Chinese networking equipment manufacturer and remains unpatched at the time of publication. It is one of the most worrying recent cases of hidden backdoors in networking equipment.

Tenda Router hidden backdoor vulnerability CVE-2026-11405 firmware

According to the CERT Coordination Center (CERT/CC), an attacker could exploit this vulnerability to bypass the password verification process and gain full administrative control without valid credentials. The backdoor is embedded in the firmware and is not visible through any administrative interface, making it particularly dangerous. The discovery was made by an anonymous researcher who reported the issue to the relevant authorities.

The issue affects a wide range of users, as Tenda routers are widely used in home and business environments around the world. The lack of a security update from the manufacturer leaves millions of devices exposed to potential attacks, while the nature of the backdoor suggests that it may have been there for a long time without being detected.

See also: Alibaba bans Claude Code due to alleged backdoor risk

The affected firmware versions are:

  • US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD
  • US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE
  • US_AC10V1.0re_V15.03.06.46_multi_TDE01
  • US_AC5V1.0RTL_V15.03.06.48_multi_TDE01
  • US_AC6V2.0RTL_V15.03.06.51_multi_T

Tenda Router: How the hidden backdoor works – CVE-2026-11405

The backdoor is located within the “login()” function of the “/bin/httpd” web server binary. During normal execution flow, the method follows a standard authentication path using MD5 -based password verification . However, if this verification fails, an alternative code path is triggered that constitutes the backdoor itself.

Specifically, the alternative path calls the “GetValue(“sys.rzadmin.password”)” to retrieve an alternative password value from the device configuration. It then performs a direct plaintext between the password provided by the user and the value stored in the configuration. If these values ​​match, the application grants administrator-level access (role=2) and creates a valid session with elevated privileges.

One particularly concerning aspect is that the associated username “rzadmin” is not verified. Therefore, any username will be accepted when combined with the backdoor password.

Graphican backdoor

Tenda Router: Risks and Impacts of the Vulnerability

Successful exploitation of this username verification bypass allows full administrative access to the device's web interface, regardless of the account credentials . A malicious actor could perform unauthorized remote configuration modification, disable security features, or reconfigure the device, potentially leading to complete device takeover.

See also: Chinese Hackers Installed Hidden Backdoor in Linux Login Software for Nearly a Decade

In practical terms, this means that an attacker could redirect network traffic, monitor user data, install malware , or use the device as a launching pad for further attacks within the internal network. In corporate environments, such a breach could lead to sensitive data leaks or ransomware attacks. It is worth noting that automated scanners targeting known default IP can detect and exploit vulnerable devices without human intervention.

The vulnerability is part of a broader pattern of troubling findings in Chinese-made networking equipment. In recent years, several manufacturers have been the focus of investigations for built-in backdoors or weak security practices, raising questions about the hardware and software supply chain

Tenda Router: Protection and recommendations for users

Since no security update is available, CERT/CC recommends that users take other protective measures. First, it is recommended to disable remote management on the device to prevent access from the internet. Second, changing the default LAN IP address can reduce the risk of detection by automated scanners targeting known default IP ranges.

See also: FlutterShell Backdoor Spreads on macOS via Malicious Google and YouTube Ads

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Tenda Router: Hidden backdoor in router firmware

Additionally, users should regularly monitor device logs for suspicious activity and consider replacing the device with alternative equipment from manufacturers with a proven security track record. Network segmentation is also a good practice to limit the potential damage in the event of a breach. Organizations using Tenda routers in business environments should immediately assess their exposure and proceed with replacement if feasible.

According to The Hacker News, the case once again highlights the importance of transparency from network equipment manufacturers and the need for stricter security controls on the firmware of the devices we use every day.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS