# CVE-2026-11405: Undocumented Authentication Backdoor in Tenda Router Firmware (FH1201, W15E, AC10, AC5, AC6)

> Tenda router firmware across the FH1201, W15E, AC10, AC5, and AC6 series contains an undocumented backdoor in the /bin/httpd login() function: when standard MD5-based authentication fails, the web server falls back to retrieving a secondary password via GetValue("sys.rzadmin.password") and compares it with plaintext strcmp() while never validating the supplied username, letting any attacker authenticate as an arbitrary user with the backdoor password and obtain role=2 administrative access. No official patch was available at disclosure and Tenda did not respond to CERT/CC coordination attempts.

- **Published:** 2026-07-10T00:00:00Z
- **Last reviewed:** 2026-07-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1188
- **ID:** TL-2026-1188
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-11405

## Description

CVE-2026-11405 is an undocumented, hardcoded authentication backdoor embedded in the `/bin/httpd` web-management binary shipped on multiple Tenda consumer/SOHO router models: FH1201, W15E, AC10, AC5, and AC6. Under normal operation, the `login()` function verifies administrator credentials via MD5-based password hashing. However, when that primary check fails, an undocumented alternate code path activates: the binary calls `GetValue("sys.rzadmin.password")` to pull a secondary, device-configuration-stored password value, then compares it against the attacker-supplied password using a plaintext `strcmp()` rather than any hashed or constant-time comparison. Critically, the associated username field is never validated in this fallback path — an attacker can submit any arbitrary username (research indicates the backdoor account is internally tied to the identity "rzadmin") together with the correct backdoor password and be granted a valid, fully privileged administrative session (role=2).

Because the backdoor is compiled directly into the firmware binary across at least five build lines (US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD, US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE, US_AC10V1.0re_V15.03.06.46_multi_TDE01, US_AC5V1.0RTL_V15.03.06.48_multi_TDE01, and US_AC6V2.0RTL_V15.03.06.51_multi_T), it cannot be disabled through any device configuration option and persists regardless of the administrator password the owner sets. CERT/CC published Vulnerability Note VU#213560 on 2026-07-06 after being unable to coordinate disclosure with Tenda; no official firmware patch had been released as of the most recent reporting (2026-07-09).

Full administrative access via this backdoor enables an attacker to reconfigure network settings, redirect or intercept traffic (adversary-in-the-middle positioning), disable security controls such as firewalling and access restrictions, and push malicious or trojanized firmware images to the device, effectively achieving persistent control of the network edge. Rescana's exploitation-tracking advisory documented widespread automated scanning activity targeting UDP port 7329 and outbound connections from compromised routers to unspecified external infrastructure beginning as early as February 2026, though no attributed threat actor, malware family, C2 domain, IP address, or file hash had been publicly disclosed at the time of this research. Interim mitigations recommended by CERT/CC are limited to disabling remote web management and changing the default LAN IP address to reduce automated-scanner discoverability, since no configuration change eliminates the underlying backdoor.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1195.003 Compromise Hardware Supply Chain
- T1046 Network Service Discovery
- T1556 Modify Authentication Process
- T1554 Compromise Host Software Binary
- T1078 Valid Accounts
- T1685 Disable or Modify Tools
- T1556 Modify Authentication Process
- T1584.008 Network Devices
- T1071 Application Layer Protocol
- T1557 Adversary-in-the-Middle
- T1495 Firmware Corruption
- T1021 Remote Services
- T1595.001 Scanning IP Blocks
- T1105 Ingress Tool Transfer

## Sources

- [Tenda Authentication Backdoor Grants Access](https://cybersecuritynews.com/tenda-authentication-backdoor-grants-access/)
- [VU#213560 - Tenda firmware (multiple versions) contains hidden authentication backdoor](https://kb.cert.org/vuls/id/213560)
- [CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware](https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html)
- [Active Exploitation Alert: Hidden Admin Backdoor (CVE-2026-11405) in Tenda Router Firmware Enables Unauthenticated Remote Access](https://www.rescana.com/post/active-exploitation-alert-hidden-admin-backdoor-cve-2026-11405-in-tenda-router-firmware-enables-unauthenticated-remote-a)
- [When the Password Check Fails, You're In: The Hidden Admin Backdoor in Tenda Router Firmware (CVE-2026-11405)](https://darkwebinformer.com/when-the-password-check-fails-youre-in-the-hidden-admin-backdoor-in-tenda-router-firmware-cve-2026-11405/)
- [Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available](https://securityaffairs.com/194878/security/hidden-tenda-router-backdoor-grants-admin-access-no-patch-available.html)
- [Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices](https://www.securityweek.com/unpatched-backdoor-in-tenda-firmware-grants-admin-access-to-devices/)
- [CVE-2026-11405: CERT Warns Of Tenda Firmware Backdoor](https://thecyberexpress.com/cve-2026-11405-cert-tenda-firmware-backdoor/)
- [CVE-2026-11405: Tenda Undocumented Authentication Backdoor](https://securityonline.info/cve-2026-11405-tenda-authentication-backdoor/)
- [Tenda Firmware Backdoor Lets Anyone Log In as Admin Regardless of Password](https://www.techtimes.com/articles/319872/20260707/tenda-firmware-backdoor-lets-anyone-log-admin-regardless-password.htm)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1188
