Undocumented backdoor in Tenda firmware allows admin access

Researcher found an undocumented backdoor in several Tenda firmware versions that bypasses web authentication and grants admin access to routers, switches and other network devices.

A security researcher discovered an undocumented backdoor in multiple Tenda firmware versions that allows attackers to bypass the web login and obtain administrative access to routers, switches and other network devices. The flaw is tracked as CVE-2026-11405.

The CERT Coordination Center at Carnegie Mellon University (CERT/CC) reported the vulnerable code is in the web server binary’s login function. When an initial authentication attempt fails, the login mechanism reads a password value from the device configuration and compares only the user-supplied password to that stored value in plaintext. If the passwords match, the code grants administrative access without validating the username. “The associated username is not validated, so any provided username will succeed when paired with the backdoor password. This backdoor authentication mechanism is not documented or visible through any administrative interface,” CERT/CC wrote.

Exploitation lets an attacker change device configuration and network settings, disable security features and control the device web management interface, which can lead to local network compromise. CERT/CC reported it was unable to coordinate disclosure with Tenda and that no patch has been released for the vulnerability.

CERT/CC and the researcher recommend disabling remote web management so the web interface is not exposed to the internet, changing the default LAN IP address to reduce the chance of discovery by automated scanners, and monitoring vendor firmware updates. Administrators should apply patches when they become available and consider isolating consumer-grade networking devices from critical network segments until fixes are issued.

In a related disclosure, CERT/CC reported a separate missing-authorization flaw in HP DeskJet 2800 series printers running firmware up to TBP1CN2612AR, tracked as CVE-2026-13753. Unauthenticated GET requests to backend API endpoints can return administrator-level configuration data, including Wi‑Fi Direct SSIDs, plaintext passphrases, printer serial numbers, service IDs and the state of administrative passwords. No patch for the printer issue had been released at the time of the report.

Users of affected Tenda devices should check device settings now, follow the recommended mitigations and monitor vendor advisories for updates that address CVE-2026-11405.

Articles by this author