hacker-news · Crawled Jul 7, 2026
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
1 IoCs
Read original article ↗
AI Summary
CERT/CC has warned of a hidden administrative backdoor in multiple Tenda router firmware versions, tracked as CVE-2026-11405. The backdoor resides in the '/bin/httpd' binary and allows full administrative access by bypassing normal authentication using an undocumented 'rzadmin' password check. The vulnerability enables attackers to gain elevated privileges without valid credentials, leading to potential device takeover. No patch is currently available, and users are advised to disable remote management and change default LAN IP settings.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | /bin/httpd | Details → |