Threat reportVulnerabilityTL-2026-1188

CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)

criticalACTIVE

CVE-2026-11405 (TL-2026-1188), also tracked as Tenda rzadmin Backdoor, is a critical-severity software vulnerability, first published 2026-07-10. It has no confirmed attribution, affects Tenda FH1201, references 1 CVE (CVE-2026-11405), maps to 14 MITRE ATT&CK techniques (T1021, T1046, T1071), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-1188

Threat ID
TL-2026-1188
Also known as
Tenda rzadmin Backdoor
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
consumer, small-office-home-office, residential
Target regions
Global
Detection rules
9
Indicators of compromise
29

Malware and tooling in CVE-2026-11405

Malware and tooling: tenda-backdoor.nse

How CVE-2026-11405 works

Tenda router firmware across the FH1201, W15E, AC10, AC5, and AC6 series contains an undocumented backdoor in the /bin/httpd login() function: when standard MD5-based authentication fails, the web server falls back to retrieving a secondary password via GetValue("sys.rzadmin.password") and compares it with plaintext strcmp() while never validating the supplied username, letting any attacker authenticate as an arbitrary user with the backdoor password and obtain role=2 administrative access. No official patch was available at disclosure and Tenda did not respond to CERT/CC coordination attempts.

CVE-2026-11405 is an undocumented, hardcoded authentication backdoor embedded in the `/bin/httpd` web-management binary shipped on multiple Tenda consumer/SOHO router models: FH1201, W15E, AC10, AC5, and AC6. Under normal operation, the `login()` function verifies administrator credentials via MD5-based password hashing. However, when that primary check fails, an undocumented alternate code path activates: the binary calls `GetValue("sys.rzadmin.password")` to pull a secondary, device-configuration-stored password value, then compares it against the attacker-supplied password using a plaintext `strcmp()` rather than any hashed or constant-time comparison. Critically, the associated username field is never validated in this fallback path — an attacker can submit any arbitrary username (research indicates the backdoor account is internally tied to the identity "rzadmin") together with the correct backdoor password and be granted a valid, fully privileged administrative session (role=2).

Because the backdoor is compiled directly into the firmware binary across at least five build lines (US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD, US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE, US_AC10V1.0re_V15.03.06.46_multi_TDE01, US_AC5V1.0RTL_V15.03.06.48_multi_TDE01, and US_AC6V2.0RTL_V15.03.06.51_multi_T), it cannot be disabled through any device configuration option and persists regardless of the administrator password the owner sets. CERT/CC published Vulnerability Note VU#213560 on 2026-07-06 after being unable to coordinate disclosure with Tenda; no official firmware patch had been released as of the most recent reporting (2026-07-09).

Full administrative access via this backdoor enables an attacker to reconfigure network settings, redirect or intercept traffic (adversary-in-the-middle positioning), disable security controls such as firewalling and access restrictions, and push malicious or trojanized firmware images to the device, effectively achieving persistent control of the network edge. Rescana's exploitation-tracking advisory documented widespread automated scanning activity targeting UDP port 7329 and outbound connections from compromised routers to unspecified external infrastructure beginning as early as February 2026, though no attributed threat actor, malware family, C2 domain, IP address, or file hash had been publicly disclosed at the time of this research. Interim mitigations recommended by CERT/CC are limited to disabling remote web management and changing the default LAN IP address to reduce automated-scanner discoverability, since no configuration change eliminates the underlying backdoor.

MITRE ATT&CK techniques used in TL-2026-1188

Lateral Movement

T1021 Remote Services

Discovery

T1046 Network Service Discovery

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1195.003 Compromise Hardware Supply Chain

Persistence

T1078 Valid Accounts; T1554 Compromise Host Software Binary

Impact

T1495 Firmware Corruption

Credential Access

T1556 Modify Authentication Process

defense-impairment

T1556 Modify Authentication Process; T1685 Disable or Modify Tools

Collection

T1557 Adversary-in-the-Middle

Resource Development

T1584.008 Network Devices

Reconnaissance

T1595.001 Scanning IP Blocks

Affected products and versions in CVE-2026-11405

  • Tenda — FH1201
    Vulnerable versions: US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD
  • Tenda — W15E
    Vulnerable versions: US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE
  • Tenda — AC10
    Vulnerable versions: US_AC10V1.0re_V15.03.06.46_multi_TDE01
  • Tenda — AC5
    Vulnerable versions: US_AC5V1.0RTL_V15.03.06.48_multi_TDE01
  • Tenda — AC6
    Vulnerable versions: US_AC6V2.0RTL_V15.03.06.51_multi_T

Remediation for CVE-2026-11405

Patches

  • No official Tenda firmware patch available as of 2026-07-09

Immediate actions

  • Disable remote/WAN-facing web management on affected Tenda devices
  • Change the device's default LAN IP address to reduce discoverability by automated scanners
  • Block or monitor outbound/inbound traffic on UDP port 7329 at the network perimeter
  • Segment or isolate affected routers from sensitive internal network segments

Workarounds

  • Disable remote web management
  • Change default LAN IP address
  • Restrict management interface access to trusted internal hosts only via firewall/ACL

Longer-term hardening

  • Replace affected Tenda hardware if no vendor patch is released
  • Deploy network-level monitoring for anomalous administrative-session establishment on SOHO/edge devices
  • Maintain an inventory of embedded/SOHO network devices and their firmware versions for rapid future patching

CVEs associated with CVE-2026-11405

CVE-2026-11405

Weaknesses (CWE) in CVE-2026-11405

CWE-798, CWE-288, CWE-306

Timeline of CVE-2026-11405

  • Rescana's exploitation-tracking advisory reports initial automated scanning activity targeting devices later identified as vulnerable to CVE-2026-11405 beginning as early as February 2026, prior to public disclosure.
  • CERT/CC notifies Tenda of the undocumented /bin/httpd authentication backdoor via its coordinated vulnerability disclosure process; Tenda does not issue a statement or acknowledgment in response.
  • CVE-2026-11405 is assigned and CERT/CC publishes Vulnerability Note VU#213560 describing the undocumented Tenda /bin/httpd login() authentication backdoor after being unable to coordinate disclosure with Tenda.
  • Rescana documents widespread automated scanning targeting UDP port 7329 and outbound connections from compromised routers to unspecified external infrastructure, though no attributed threat actor, IP, domain, or hash is publicly disclosed.
  • Cyber Security News, The Hacker News, SecurityOnline.info, TheCyberExpress, TechTimes, and DarkWebInformer publish coverage of the backdoor, detailing the strcmp() plaintext comparison and username-bypass mechanism.
  • CERT/CC (Carnegie Mellon University) formally warns of the hidden admin backdoor, confirming affected models FH1201, W15E, AC10, AC5, and AC6 and noting no vendor response.
  • SecurityAffairs publishes further analysis confirming the backdoor is hardcoded into firmware binaries and cannot be disabled via the management interface.
  • SecurityWeek reports that no official Tenda firmware patch has been released and that CERT/CC was unable to coordinate disclosure with the vendor; only interim mitigations remain available.

Sources cited for CVE-2026-11405

Detection coverage for TL-2026-1188

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1188 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats