Overview
- The CERT Coordination Center published an advisory on July 6, 2026, assigning CVE-2026-11405 after an anonymous researcher reported an undocumented authentication backdoor in Tenda firmware.
- The flaw lives in the router web server binary /bin/httpd where the login() routine reads sys.rzadmin.password and compares it in plaintext to grant role=2 administrative access without validating the username.
- CERT/CC named specific vulnerable firmware builds spanning Tenda FH1201, W15E, AC10, AC5 and AC6 product lines while noting the listed builds may not be exhaustive.
- Tenda did not respond to coordination requests and no patch was available at disclosure, so CERT/CC advises disabling remote web management, reducing local exposure such as changing default LAN IPs, or replacing devices if the risk is unacceptable.
- Because full admin control lets attackers change DNS, disable security features and pivot to devices on the local network, the bug heightens real-world risks for homes and small businesses and feeds broader supply-chain security concerns regulators have raised.