Hidden Backdoor Authentication in Web Server Binary by Vendor
CVE-2026-11405
Key Information:
Badges
What is CVE-2026-11405?
CVE-2026-11405 is a serious vulnerability found in the web server binary of Tenda products, specifically within the login function. This vulnerability incorporates a hidden backdoor authentication mechanism that could be exploited by attackers to gain unauthorized administrative access to affected systems. The normal authentication process uses standard MD5 hashing for password verification. However, if this process fails, the vulnerability allows the system to read a backdoor password directly from the device's configuration. This is done via a plaintext comparison, meaning that any username can be used alongside the backdoor password to achieve admin-level access without proper authorization. This poses a severe risk to organizations, as it can lead to unauthorized manipulation and control of sensitive web-based applications.
Potential impact of CVE-2026-11405
-
Unauthorized Administrative Access: The hidden backdoor allows attackers to bypass normal authentication mechanisms, granting them administrative rights. This can lead to malicious actors executing commands, altering configurations, or accessing sensitive data without detection.
-
Data Breaches: Since the vulnerability grants high-level access to the web server, attackers could extract sensitive information stored within the system. This can result in significant data breaches affecting user privacy and compliance with regulations such as GDPR.
-
Increased Risk of Malware Deployment: With the ability to control the server, an attacker can deploy additional malware, such as ransomware, potentially spreading to connected networks and severely disrupting organizational operations.
Affected Version(s)
firmware US_AC6V2.0RTL_V15.03.06.51_multi_T
firmware US_AC5V1.0RTL_V15.03.06.48_multi_TDE01
firmware US_AC10V1.0re_V15.03.06.46_multi_TDE01
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
This Week In Security: Escaping Linux VMs, Vulnerable Solar, Confusing AI (Again), And Confusing NPM Malware
The Januscape vulnerability allows a user in a guest VM managed by the Linux Kernel Virtual Machine (KVM) to corrupt memory in the host system and break out of isolation. KVM virtualization is used…
3 weeks ago
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices - IT Security News
Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device’s web management interface. The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the…Read more...
3 weeks ago
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
Multiple Tenda firmware versions contain a backdoor (CVE-2026-11405) that provides access to the device’s web management interface.
3 weeks ago
References
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved