bleeping-computer · Crawled Jul 7, 2026

Hidden backdoor in Tenda router firmware grants admin access

Read original article ↗

AI Summary

A hidden authentication backdoor in multiple Tenda router firmware versions allows attackers to gain full administrative access to the device's web interface by using an undocumented password comparison mechanism. The vulnerability, tracked as CVE-2026-11405, is located in the '/bin/httpd' binary and remains unpatched as the vendor could not be reached. Successful exploitation enables attackers to reconfigure the device, alter network settings, and disable security features, posing significant risk to the local network.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.