Research has discovered that several Tenda Wi-Fi routers are at risk of being compromised as a result of an undocumented authentication backdoor embedded in their firmware. An attacker can bypass the normal login process and gain administrator-level access to affected devices through this flaw, and no official security patch has been released yet.
A US-based cybersecurity authority, CERT/CC (CERT/CC), identified the vulnerability and released it as a security advisory. According to the advisory, the backdoor is present in five firmware versions of older Tenda router models. A CVE-2026-11405 vulnerability has been assigned to this vulnerability.
It is reported that the vulnerability is associated with the web server’s login function, where a failed authentication attempt triggers a secondary verification process for passwords. Instead of validating both the username and password, firmware only checks the password value stored within the device configuration, which enables authentication to be successful regardless of the username used.
In the case of Tenda devices, access is normally limited to administrator credentials via the web-based management interface. It has been discovered that the firmware contains an undocumented authentication mechanism that is activated upon failure of a standard login attempt. The firmware compares only a password stored in the device configuration, rather than validating both the username and password. Regardless of the username entered, administrative access is granted if the supplied password matches.
Interestingly, researchers noted that the alternative password appears to be “rzadmin”, which has previously been discovered in previous security research involving Tenda devices. However, since the authentication process does not validate the username, any username can successfully login when paired with the appropriate backdoor password. Despite the device’s administrative interface, hidden functionality is not documented or disclosed.
Upon matching the alternate password with the device configuration value, the firmware grants full administrator privileges and creates a valid management session. Because of its undocumented nature and inaccessibility through the standard administrative interface, it has been classified as an authentication backdoor by researchers.
During previous security research involving Tenda devices, the alternate password was identified as “rzadmin”, a credential that has previously surfaced. Despite the lack of clear explanations for its presence, experts believe it may have been accidentally left behind as part of a debugging or development tool.
One of the biggest concerns is the lack of a vendor response. According to CERT/CC, they were unable to reach Tenda to coordinate a fix, resulting in the non-availability of official firmware updates for affected users. As a result, this vulnerability remains unpatched. Successful exploitation could result in router configuration changes, network settings changes, security settings being disabled, and potentially compromise other local networks.
A security expert considers this vulnerability to be a significant risk for exposed devices due to its ability to grant administrator-level privileges without standard authentication. This firmware is affecting a variety of Tenda networking products, including routers, wireless hotspots, and other networking equipment. […]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
Content was cut in order to protect the source.Please visit the source for the rest of the article.
This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents
Read the original article:
