Cyber Security News

Tenda Authentication Backdoor Grants Attackers Full Administrative Access

A newly disclosed vulnerability in Tenda network devices exposes a critical authentication backdoor that allows attackers to gain full administrative access without valid credentials.

The flaw affects multiple firmware versions across several Tenda router models, including the FH1201, W15E, AC10, AC5, and AC6 series.

The issue, tracked as CVE-2026-11405, was published by the CERT Coordination Center under Vulnerability Note VU#213560 on July 6, 2026.

These routers are widely used in home and small business environments, where they rely on web-based management interfaces secured by username and password authentication.

According to the advisory, the vulnerability exists within the web server binary located at /bin/httpd. Specifically, the issue lies in the login () function, which contains an undocumented authentication mechanism.

Tenda Backdoor Grants Admin Access

Under normal conditions, the function validates user credentials using an MD5-based password verification process. However, when authentication fails, the function follows an alternate execution path that introduces a hidden backdoor.

This backdoor retrieves a secondary password value from the device configuration using the GetValue(“sys.rzadmin.password”) function.

Instead of applying standard hashing or secure comparison, the system performs a direct plaintext strcmp() comparison between the supplied password and the stored value.

If the comparison succeeds, the system grants administrative privileges by assigning role=2 and creates a valid session.

A critical aspect of this vulnerability is that the username is not validated during this fallback process. This means an attacker can use any arbitrary username alongside the backdoor password to gain full administrative control.

The presence of this mechanism is not documented. It cannot be identified through the standard administrative interface, making it particularly dangerous.

Successful exploitation enables attackers to compromise affected devices fully. With administrative access, attackers can modify network configurations, redirect traffic, turn off security controls, or deploy malicious firmware.

This level of control can facilitate broader attacks, including man-in-the-middle interception, persistence within the network, and lateral movement to other connected systems.

At the time of disclosure, no official patch or firmware update has been released by Tenda, and attempts to coordinate with the vendor were unsuccessful.

As a result, users are advised to take immediate mitigation steps to reduce exposure. Security experts recommend turning off remote web management features to prevent external access to the device’s interface.

Additionally, changing the default local IP address may reduce the likelihood of automated scanning attacks targeting known address ranges. However, it does not stop determined attackers.

The discovery of these hidden backdoors raises serious concerns about firmware security practices and the trustworthiness of the supply chain.

Users and organizations relying on affected Tenda devices should closely monitor for updates and consider replacing vulnerable hardware if no fix becomes available.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

20 minutes ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

1 hour ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

3 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

3 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

3 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

3 hours ago