{"id":1627,"date":"2026-07-07T08:36:38","date_gmt":"2026-07-07T08:36:38","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1627"},"modified":"2026-07-07T08:36:38","modified_gmt":"2026-07-07T08:36:38","slug":"cert-cc-warns-of-hidden-admin-backdoor-in-tenda-router-firmware","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1627","title":{"rendered":"CERT\/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 07, 2026<\/span><\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEibED37Q9WinxGoPYaXltP_givD-Q30FneMyezHB4uftr5E4hy4fMm97v_UH34sQWEvlp688bYvMR6zDzy_C93ddbqNDfIVSX7swJgdTD38hOmKgu6ZLGjBW068gXHpsT4soRscJ1vWDxTz2z8xBDSb2QD2UWrR68nVytui4mo6Q0cXVh_GjK5FC6P4imvK\/s1700-e365\/backdoor-admin.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices&#8217; web management interfaces, the CERT Coordination Center (CERT\/CC) warned Monday.<\/p>\n<p>\u00abAn attacker can exploit this vulnerability, tracked as <b><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-11405\">CVE-2026-11405<\/a><\/b>, to bypass the password verification process and obtain full administrative control without valid credentials,\u00bb the CERT\/CC <a href=\"https:\/\/kb.cert.org\/vuls\/id\/213560\">said<\/a> in an alert.<\/p>\n<p>The vulnerability impacts multiple versions of the firmware &#8211;<\/p>\n<ul>\n<li>US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD<\/li>\n<li>US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE<\/li>\n<li>US_AC10V1.0re_V15.03.06.46_multi_TDE01<\/li>\n<li>US_AC5V1.0RTL_V15.03.06.48_multi_TDE01<\/li>\n<li>US_AC6V2.0RTL_V15.03.06.51_multi_T<\/li>\n<\/ul>\n<p>The backdoor functionality is present within the \u00ablogin()\u00bb function of the \u00ab\/bin\/httpd\u00bb web server binary. While the method initially follows a normal authentication path using MD5-based password verification, it activates an alternate code path if the authentication fails.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqmM4NpfZsx4cw-HrXQlCjZQmrF8bYnmB23AmpOPi16kPNB9lvICjpdYEclxJwyQ9OE8GgzQ8aOEI68tRuxNqov0MHz2Sq8xEPiYWM3Js6FM5t2nm2JHWodmR7qVSot14ZtWVqQRQ6B88OnMaVxCPwRG7xGPoIIZxF6QAhWVhMkQfs11NjyNtHsGEUH4_q\/s728-e100\/sygnia-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Specifically, this involves calling \u00abGetValue(\u00absys.rzadmin.password\u00bb)\u00bb to fetch an alternate password value from the device configuration, and performing a direct plaintext comparison between the user-supplied password and the configuration-stored value. Should these values match, the application grants admin-level access (role=2) and creates a valid session with elevated privileges.<\/p>\n<p>\u00abThe associated [\u00abrzadmin\u00bb] username is not validated, so any provided username will succeed when paired with the backdoor password,\u00bb the CERT\/CC said. \u00abThis backdoor authentication mechanism is not documented or visible through any administrative interface.\u00bb<\/p>\n<p>Successful exploitation of this standard username validation override allows full administrative access to the device&#8217;s web interface regardless of the administrator account credentials. It can permit an attacker to make unauthorized remote modification of settings, disable security features, or reconfigure the device, potentially leading to a complete device takeover.<\/p>\n<p>The vulnerability, reported by an anonymous researcher, remains unpatched as of writing. The Hacker News has contacted Tenda for comment, and we will update the story if we hear back.<\/p>\n<p>In the interim, users are advised to disable remote management on the device and change the default LAN IP address to prevent bad actors from reaching it and reduce opportunistic discovery by automated scanners that target known default IP ranges.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 07, 2026 Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1628,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[129,179,2382,2384,844,697,2383,148],"class_list":["post-1627","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-admin","tag-backdoor","tag-certcc","tag-firmware","tag-hidden","tag-router","tag-tenda","tag-warns"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1627","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1627"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1627\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1628"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1627"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1627"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1627"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}