CVE-2026-11405Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor

7.8/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 33 mentions across 10 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 27 signals
  • Disclosure: 20 classified signals
  • General: 6 classified signals
  • Peaked 9d ago at 11 mentions (2026-07-07); latest day: 1
  • 33 total mentions across 10 days

Deep dive

Activity timeline33 mentions / 10d
036811Mentions · 2026-07-07: 11Mentions · 2026-07-08: 7Mentions · 2026-07-09: 6Mentions · 2026-07-10: 2Mentions · 2026-07-13: 1Mentions · 2026-07-15: 1Mentions · 2026-07-18: 1Mentions · 2026-07-19: 1Mentions · 2026-07-20: 2Mentions · 2026-08-06: 1PoC Mentioned / Linked · 2026-07-19: 1PoC Mentioned / Linked · 2026-07-20: 1Exploit Tool / Code · 2026-07-19: 1Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-07-08: 1Active Exploitation · 2026-07-10: 1Patch / Workaround · 2026-07-07: 3Patch / Workaround · 2026-07-08: 2Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-18: 1Patch / Workaround · 2026-07-19: 1Patch / Workaround · 2026-07-20: 1Technical Details · 2026-07-07: 10Technical Details · 2026-07-08: 5Technical Details · 2026-07-09: 6Technical Details · 2026-07-10: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-18: 1Technical Details · 2026-07-19: 1Technical Details · 2026-07-20: 207-0707-0807-0907-1007-1307-1507-1807-1907-2008-06
Signal classification4 categories
Disclosure
2060.6%
General
618.2%
Patch
412.1%
Active Exploitation
39.1%
Referenced assets33 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-0711
Active Exploitation1Disclosure9General1
2026-07-087
Active Exploitation1Disclosure3General1Patch2
2026-07-096
Disclosure5General1
2026-07-102
Active Exploitation1Patch1
2026-07-131
Disclosure1
2026-07-151
General1
2026-07-181
Disclosure1
2026-07-191
General1
2026-07-202
Disclosure1Patch1
2026-08-061
General1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    🛑 WARNING - Several Tenda firmware builds embed an undocumented auth backdoor in /bin/httpd. CVE-2026-11405 checks sys.rzadmin.password after normal login fails. If the supplied password matches, it creates an admin session. Still unpatched. Read: https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html https://t.co/5gCE1HSVpW

    Post summary

    The text discloses that CVE-2026-11405 is an undocumented authentication backdoor in Tenda firmware that auto-creates an admin session when the correct password is supplied after a failed normal login, and notes the vulnerability remains unpatched.

    77522446842.1K
    2.3M followersView on X
  • Co11ateral@co11ateral
    Disclosure

    Tenda Routers - CVE-2026-11405 There are over 12,000 Tenda routers indexed on Shodan, with most of them found in the United States Recent Tenda vulnerabilities have continued to make headlines. One of the latest is CVE-2026-11405, which allows to bypass MD5 password verification and use a hidden alternate password to gain full administrative privileges (role=2) through the web interface Tenda has remained silent since they were contacted in May 2026 In our article, we take a closer look at Tenda's security and explore what else has been happening with its products https://hackers-arise.com/router-hacking-why-the-worlds-most-popular-budget-router-keeps-making-headlines-for-the-wrong-reasons/ @three_cube @_aircorridor #zeroday

    Post summary

    The text discloses CVE‑2026‑11405, explaining its authentication bypass via MD5 verification and granting admin rights through the web interface, but provides no PoC, exploit, patch, or evidence of active exploitation.

    17032172.2K
    11.5K followersView on X
  • Dark Web Informer@DarkWebInformer
    General

    ‼️ When the Password Check Fails, You're In: The Hidden Admin Backdoor in Tenda Router Firmware (CVE-2026-11405) https://darkwebinformer.com/when-the-password-check-fails-youre-in-the-hidden-admin-backdoor-in-tenda-router-firmware-cve-2026-11405/

    Post summary

    The provided snippet announces a hidden admin backdoor CVE‑2026‑11405 in Tenda router firmware, but offers no further technical, exploit, or remediation details.

    06031610.6K
    234.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-11405 is a Tenda authentication backdoor. It allows full administrative access without valid credentials. Protect your network with these steps. #CVE202611405 #Tenda #AuthenticationBackdoor #CyberSecurity #RouterSecurity http://securityonline.info/cve-2026-11405-tenda-authentication-backdoor/

    Post summary

    CVE‑2026‑11405 is disclosed as a Tenda authentication backdoor permitting full admin access without credentials. The post offers protection tips but lacks PoC, exploit code, active exploitation evidence, or patch details.

    021122926
    12.9K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Tendaの複数ファームウェアに、通常のパスワード確認を迂回する未文書化の認証バックドアが隠されていたと報告された。CVE-2026-11405として追跡され、正規の認証情報なしにWeb管理画面を乗っ取れる恐れがある。 問題はWebサーバーバイナリ/bin/httpdのlogin()関数にある。通常のMD5パスワード検証に失敗した後、同関数は設定値sys.rzadmin.passwordと入力されたパスワードを照合する。この隠し値と一致すると、レベル2の管理者アクセスが許可される。 この処理ではユーザー名が検証されないため、任意のユーザー名と秘密のパスワードを組み合わせるだけで有効なセッションを作成できる。攻撃者がルーターのWebインターフェースへ到達できる場合、管理画面に入り、ネットワーク設定の変更や重要なセキュリティ機能の無効化が可能になる。 アドバイザリは、影響を受けるファームウェアとしてFH1201、W15E、AC10、AC5、AC6の各モデルの5バージョンを挙げている。TendaはCVE-2026-11405向けのパッチを公開していない。 緩和策として、管理者には外部からの攻撃を防ぐためリモートWeb管理を無効化すること、ローカルネットワーク上の自動スキャナーによる発見を減らすため既定のLAN IPアドレスを変更することが求められている。 https://securityonline.info/cve-2026-11405-tenda-authentication-backdoor/

    Post summary

    The post discloses a hidden authentication backdoor in multiple Tenda firmware versions (CVE-2026‑11405), detailing how it bypasses password checks to grant admin access, while providing mitigation steps and noting the lack of a vendor patch.

    010321.8K
    14.9K followersView on X
  • Mr. OS@ksg93rd
    General

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (July 05 - 18, 2026) 1⃣  NGINX Vulnerability https://www.penligent.ai/hackinglabs/cve-2026-42533/ // NGINX map Directive Heap Overflow and Data Plane Risk (CVE-2026-42533) 2⃣  Zoom Account Takeover Patch https://www.zoom.com/en/trust/security-bulletin/zsb-26014 // CVE-2026-53412 (CVSS 9.8) 3⃣  Firewalld 2.5.0 https://github.com/firewalld/firewalld/releases/tag/v2.5.0 4⃣  Forgotten UEFI shims undermining Secure Boot https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot // 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulns 5⃣  A backdoor in Tenda firmware allows root access https://kb.cert.org/vuls/id/213560 // CVE-2026-11405 6⃣  OpenSSH 10.4 https://lists.mindrot.org/pipermail/openssh-unix-dev/2026-July/042582.html 7⃣  ASUS bsitf.sys (CVE-2026-13585) https://github.com/416rehman/asus-bsitf-0-day-poc // Arbitrary Physical Memory Mapping 0-day writeup + PoC 8⃣  SpecterOps NTLM Relay Egress Operator Guide https://specterops.io/blog/2026/07/15/there-and-back-again-an-operators-guide-on-ntlm-relaying-egress/#h-acknowledgements-and-prior-work // NTLM relay attacks are far from dead 9⃣ A collection of techniques for process injection on Windows https://github.com/toneillcodes/windows-process-injection 🔟 Clawdefender v.1.0.4 // Security scanner and input sanitizer for AI agents https://github.com/rin-proxy/clawdefender http://www.cyberpocket.org

    Post summary

    The tweet outlines several recent CVEs, providing links to PoCs, exploits, patches, and technical details, but does not assert active exploitation in the wild.

    01020180
    3.3K followersView on X
  • ohmohm@ohmohm
    General

    CVE-2026-11405 https://www.thaicert.or.th/2026/07/08/%e0%b8%8a%e0%b9%88%e0%b8%ad%e0%b8%87%e0%b9%82%e0%b8%ab%e0%b8%a7%e0%b9%88-backdoor-%e0%b9%83%e0%b8%99%e0%b9%80%e0%b8%a3%e0%b8%b2%e0%b9%80%e0%b8%95%e0%b8%ad%e0%b8%a3%e0%b9%8c-tenda-%e0%b9%80%e0%b8%9b/

    Post summary

    The text references CVE-2026-11405 and provides a link, but gives no additional details about the vulnerability, exploitation, or mitigation.

    0101159
    3.7K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🚪 Hidden backdoor found in Tenda firmware. The login() function in /bin/httpd has a hardcoded auth bypass granting full admin access — no credentials needed. CVSS 9.8. CVE-2026-11405 #IoTSecurity #Firmware https://secalerts.co/vulnerability/CVE-2026-11405?utm_campaign=x https://t.co/YUs6eC9dGF

    Post summary

    The tweet reports a hardcoded authentication bypass in Tenda firmware’s httpd login() function that allows unrestricted admin access with no credentials, rating CVE-2026‑11405 at CVSS 9.8.

    10020117
    852 followersView on X
  • Hardware Busters@HardwareBusters
    Disclosure

    Tenda Left a Backdoor in Its Own Routers — and It Hands Out Full Admin A hidden login (CVE-2026-11405) grants full admin on at least five Tenda router models, with no patch yet. https://hwbusters.com/news/tenda-left-a-backdoor-in-its-own-routers-and-it-hands-out-full-admin/

    Post summary

    The article announces a hidden backdoor in several Tenda router models (CVE-2026-11405) that allows full administrative access, with no patch released yet.

    00020212
    965 followersView on X
  • SoEmailSecurity@Soemailsecurity
    Disclosure

    Tenda router firmware has a hidden admin backdoor, affecting multiple versions, as warned by CERT/CC on Monday, what's to stop attackers from exploiting CVE-2026-11405 to bypass passwords? #RouterSecurity #Vulnerability #Cybersecurity

    Post summary

    CERT/CC warns that Tenda routers contain a hidden admin backdoor (CVE‑2026‑11405) that can bypass passwords.

    1001061
    68 followersView on X
  • Qubble@QubbleOfficial
    General

    CERT/CC: Tenda routers (CVE-2026-11405) grant unauthenticated admin. Vendor ghosted, no patch. Tom's Hardware. The break isn't the bug — it's the vendor root. Code-signing blesses the backdoor as legitimate firmware. https://t.co/R8giJTCCSX

    Post summary

    The tweet highlights a disclosed vulnerability (unauthenticated admin) in Tenda routers, notes the vendor’s silence and lack of a patch, but provides no PoC, exploit code, or evidence of active exploitation.

    1000056
    2.2K followersView on X
  • Threat ResQ™@ThreatResq
    Disclosure

    An undocumented backdoor in multiple Tenda devices allows admin access bypass. The flaw is tracked as CVE-2026-11405. https://www.securityweek.com/unpatched-backdoor-in-tenda-firmware-grants-admin-access-to-devices/ #Tenda #backdoor #bypass #vulnerability #CVE #CybersecurityNews #CyberSecurity #threatresq #ThreatResQ

    Post summary

    An undocumented backdoor in multiple Tenda devices permits admin access bypass, identified as CVE-2026-11405. No PoC, exploit, or patch details are included in the announcement.

    00010198
    46 followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-11405 is an unpatched backdoor in Tenda routers (FH1201, W15E, AC10, AC5, AC6): any username plus a hidden password in sys.rzadmin.password bypasses login and grants full admin. No patch exists; disable remote management now. #DFIR_Radar https://t.co/9L5giCEn2n

    Post summary

    The tweet announces a critical, unpatched backdoor in several Tenda router models, warns that no patch is available, and recommends disabling remote management as a mitigation.

    10000186
    1.7K followersView on X
  • Silent Vector@gh0st_V3ctbrv
    Disclosure

    CERT/CC has disclosed CVE-2026-11405, an authentication backdoor affecting several Tenda router firmware versions. Unlike many vulnerabilities, this issue stems from undocumented functionality that can bypass normal authentication and grant administrative access.

    Post summary

    CERT/CC has disclosed CVE-2026-11405, an authentication backdoor affecting several Tenda router firmware versions that uses undocumented functionality to bypass normal authentication and grant administrative access.

    1000036
    9.2K followersView on X
  • Rick Lehrbaum@RLehrbaum37632
    General

    Hacking a Tenda AC1200 Wi-Fi Router with a CVE Combo: It’s rather awkward when you buy a piece of hardware like a sketchy router to make a video about its hidden admin password backdoor – known as CVE-2026-11405 – only to discover that you bought the w… https://ift.tt/L1Romxw

    Post summary

    The post briefly notes hacking a Tenda AC1200 router via CVE-2026-11405 and points to a video, but provides no concrete exploit details, patch info, or evidence of active exploitation.

    0000082
    41 followersView on X
  • foursignals@foursignalsdev
    Patch

    Tenda routers ship with a fallback password backdoor (CVE-2026-11405). No patch for FH1201, W15E, AC10, AC5, AC6. The bypass uses a runtime config key, evading static... https://www.foursignals.dev/wire/2026-07-20/the-fallback-password-dissecting-the-tenda-router-backdoor-c093df

    Post summary

    The post discloses Tenda routers contain a fallback password backdoor (CVE‑2026‑11405) and notes that no patch is available for several models, while a bypass exploits a runtime config key.

    0000056
    31 followersView on X
  • BT Haberler@BTHaberler
    Disclosure

    Beş Tenda router modelinde yerleşik "yedek şifre" keşfedildi — ve henüz yama yok! Anonim bir araştırmacı, Tenda'nın gömülü web sunucusunda (/bin/httpd) CVE-2026-11405 açığını buldu. FH1201, W15E, AC10, AC5 ve AC6 V2 modellerini etkiliyor. • Standart MD5 şifre doğrulaması başarısız olursa cihaz, sys.rzadmin.password parametresinden alternatif bir şifreyi doğrudan kullanıcı girdisiyle karşılaştırıyor. • Alternatif şifre eşleşirse kullanıcı adı doğrulaması tamamen atlanıyor — arka kapı niteliğinde bir mekanizma. • CERT/CC yayın tarihi itibarıyla henüz yama alamadı ve Tenda'ya ulaşamadı. Yama gelene kadar uzaktan yönetimi kapatın ve router'ın varsayılan yerel IP adresini değiştirin! #SiberGüvenlik #Tenda #Router

    Post summary

    The post discloses a newly found CVE-2026-11405 in several Tenda router models, explains the authentication bypass, notes no patch is available, and recommends disabling remote management as a temporary mitigation.

    00000106
    36 followersView on X
  • ACMT s.r.o.@acmtcz
    Disclosure

    Routery Tenda mají vestavěné heslo umožňující plný admin přístup bez ohledu na heslo majitele (CVE-2026-11405). Výrobce nereaguje, záplata chybí. Máte doma Tendu? https://www.root.cz/zpravicky/vestavene-heslo-v-routerech-tenda-umoznuje-pristup-k-administraci/ https://t.co/r29hdqQjRG

    Post summary

    The article reports that Tenda routers have an embedded admin password that grants full control regardless of the owner’s password (CVE‑2026‑11405), and notes that no patch is currently available.

    0000045
    14 followersView on X
  • Vistem Solutions@VistemSolutions
    Patch

    Router and edge-device backdoors are serious because they can give attackers direct access to management interfaces, configurations, traffic paths, and connected networks. CVE-2026-11405 in multiple Tenda firmware versions is a reminder that unmanaged or unpatched devices can quietly become high-risk entry points. What organizations should prioritize now: - Identify any Tenda devices in use across offices, branches, remote sites, and home-office setups - Check firmware versions and apply vendor updates or mitigations as soon as available - Remove direct internet exposure and disable unnecessary remote management - Change default credentials and rotate admin passwords, keys, and shared secrets - Monitor for unusual logins, configuration changes, DNS changes, proxy behavior, and abnormal outbound traffic - Replace unsupported or unpatchable devices with enterprise-managed hardware 𝗩𝗶𝘀𝘁𝗲𝗺 𝗘𝗹𝗲𝘃𝗮𝘁𝗲 𝗽𝗼𝘄𝗲𝗿𝗲𝗱 𝗯𝘆 𝗩𝗶𝘀𝘁𝗲𝗺𝗦𝗲𝗰𝘂𝗿𝗲𝗣𝗿𝗼 helps organizations reduce edge-device risk, strengthen network security, and improve resilience with vCISO-led strategy, continuous monitoring, and measurable outcomes. Contact: sales@vistem.com | http://www.vistem.com?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer #Cybersecurity #Tenda #RouterSecurity #FirmwareSecurity #CVE #NetworkSecurity #VulnerabilityManagement #IncidentResponse #ZeroTrust #CyberResilience #VistemElevate #VistemSecurePro #VistemSolutions #SecurityCompliance https://www.securityweek.com/unpatched-backdoor-in-tenda-firmware-grants-admin-access-to-devices/?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer

    Post summary

    The message highlights the CVE‑2026‑11405 backdoor in Tenda firmware and emphasizes the importance of applying vendor patches and following mitigation steps.

    0000069
    78 followersView on X
  • SecPod@SecPod
    Active Exploitation

    Security Alert: CVE-2026-11405 exposes a hidden admin backdoor in multiple Tenda routers, allowing attackers to gain full control without credentials. No official patch is available, and active exploitation has been reported. Take immediate mitigation steps. Read the full report here: https://www.secpod.com/learn/security-research/cve-2026-11405-actively-exploited-zero-day-hidden-admin-backdoor-threatens-tenda-routers #CyberSecurity #ZeroDay #CVE #Tenda #RouterSecurity #ThreatIntel

    Post summary

    CVE‑2026‑11405 is a hidden admin backdoor in Tenda routers currently being exploited in the wild; no official patch exists, so immediate mitigation steps are recommended.

    0000096
    544 followersView on X

Explore more