Co11ateral[verified]@co11ateralDisclosure
The text discloses CVE‑2026‑11405, explaining its authentication bypass via MD5 verification and granting admin rights through the web interface, but provides no PoC, exploit, patch, or evidence of active exploitation.
yousukezan[verified]@yousukezanDisclosure
The post discloses a hidden authentication backdoor in multiple Tenda firmware versions (CVE-2026‑11405), detailing how it bypasses password checks to grant admin access, while providing mitigation steps and noting the lack of a vendor patch.
DFIR Radar[verified]@DFIR_RadarPatch
The tweet announces a critical, unpatched backdoor in several Tenda router models, warns that no patch is available, and recommends disabling remote management as a mitigation.
Silent Vector[verified]@gh0st_V3ctbrvDisclosure
CERT/CC has disclosed CVE-2026-11405, an authentication backdoor affecting several Tenda router firmware versions that uses undocumented functionality to bypass normal authentication and grant administrative access.
BT Haberler[verified]@BTHaberlerDisclosure
The post discloses a newly found CVE-2026-11405 in several Tenda router models, explains the authentication bypass, notes no patch is available, and recommends disabling remote management as a temporary mitigation.
Vistem Solutions[verified]@VistemSolutionsPatch
The message highlights the CVE‑2026‑11405 backdoor in Tenda firmware and emphasizes the importance of applying vendor patches and following mitigation steps.
SecPod[verified]@SecPodActive Exploitation
CVE‑2026‑11405 is a hidden admin backdoor in Tenda routers currently being exploited in the wild; no official patch exists, so immediate mitigation steps are recommended.
The Hacker News@TheHackersNewsDisclosure
The text discloses that CVE-2026-11405 is an undocumented authentication backdoor in Tenda firmware that auto-creates an admin session when the correct password is supplied after a failed normal login, and notes the vulnerability remains unpatched.