- Description
- The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor
- Source
- cret@cert.org
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- Hype score
- Not currently trending
⚠️ Masz router Tenda? Sprawdź aktualizacje firmware! CVE-2026-11405 to ukryty mechanizm uwierzytelniania, który może pozwolić na uzyskanie pełnego dostępu administratora bez właściwego hasła. Producent udostępnił poprawki. https://t.co/o8UFHTqRL1 #cybersecurity #
@marekitlab
2 Aug 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
An undocumented backdoor in multiple Tenda devices allows admin access bypass. The flaw is tracked as CVE-2026-11405. https://t.co/aYqFOAwrgq #Tenda #backdoor #bypass #vulnerability #CVE #CybersecurityNews #CyberSecurity #threatresq #ThreatResQ
@ThreatResq
9 Jul 2026
65 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes