<- ALL CYBER NEWS

Critical

Tenda, CVE-2026-11405, backdoor, router, firmware, unauthenticated, botnet

Tenda Router Backdoor CVE-2026-11405: Unauth Admin Access

Tenda firmware backdoor CVE-2026-11405 (CVSS 9.8) grants unauthenticated admin access via a hidden path in /bin/httpd. No fix yet — how to protect your router.

A backdoor in multiple firmware versions from networking vendor Tenda lets unauthenticated attackers reach a device's web management interface, tracked as CVE-2026-11405, as reported by SecurityWeek. At the time of disclosure there was no patch available.

An undocumented authentication bypass baked into firmware is close to a worst case for a network device, because it is not so much a bug to be triggered as a door left in the wall. Anyone who knows it is there can walk in, and consumer routers are rarely watched for that kind of entry.

Devices like these are the raw material of botnets. Home and small-office routers with remote-reachable admin panels get swept up at scale to relay attacks, proxy malicious traffic, and hide an intruder's origin. A no-fix backdoor in a widely sold brand is precisely the sort of thing that quietly grows an operational relay network.

Until a patch ships, the defensive moves are to make sure the management interface is not exposed to the internet, disable remote administration, and segment these devices away from anything sensitive. Where firmware cannot be trusted and cannot be fixed, reducing what it can reach is the only lever left.

Sources: SecurityWeek; CERT/CC.

Affected firmware and mitigation

  • Affected: multiple Tenda router firmware versions; the backdoor lives in the web-server binary /bin/httpd, in a hidden secondary path inside the login() function (see the CERT/CC advisory for the exact model list).

  • Severity: CVSS 9.8 (Critical), unauthenticated and network-reachable.

  • Fix: none available at publication. Mitigate by removing the device from internet exposure and disabling remote administration.

A no-fix flaw on hardware that outlives its support window is the exposure window at its worst; see our analysis of the 2025 exploitation timeline for why unpatched edge devices get found first.

Frequently asked questions

Which Tenda routers are affected by CVE-2026-11405?

Multiple Tenda router firmware versions are affected. The backdoor is in the /bin/httpd web-server binary rather than a single model feature, so check the CERT/CC advisory for the exact affected model and firmware list.

Is there a patch for CVE-2026-11405?

No. As of publication there is no official fix, which is what makes this dangerous, the only defence is reducing what the device can reach.

Is CVE-2026-11405 being exploited?

It is not yet in CISA KEV, but a CVSS 9.8 unauthenticated backdoor on a widely sold home/SOHO router is exactly the profile botnets scan for. Treat it as actively targeted.

How does the Tenda backdoor actually work?

Beyond the normal MD5/hash password check, the login() function in /bin/httpd contains a hidden secondary authentication path that lets an attacker reach the admin interface without valid credentials.

How do I protect a Tenda router when there is no patch?

Make sure the management interface is not exposed to the internet, disable remote administration, segment the router away from anything sensitive, and plan to replace firmware that cannot be trusted or fixed.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.