hacker-news · Crawled Jul 7, 2026

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

1 IoCs
Read original article ↗

AI Summary

CERT/CC has warned of a hidden administrative backdoor in multiple Tenda router firmware versions, tracked as CVE-2026-11405. The backdoor resides in the '/bin/httpd' binary and allows full administrative access by bypassing normal authentication using an undocumented 'rzadmin' password check. The vulnerability enables attackers to gain elevated privileges without valid credentials, leading to potential device takeover. No patch is currently available, and users are advised to disable remote management and change default LAN IP settings.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Filename /bin/httpd Details →