Users of Tenda brand router devices are urged to increase their vigilance following the discovery of a serious security vulnerability in their firmware systems. This hidden vulnerability, known as a 'backdoor', has the potential to grant unauthorized parties full access to take over the device's administrative control.
The vulnerability, registered in the global security system as CVE-2026-11405, was first identified by the CERT Coordination Center (CERT/CC). According to the agency's report, this vulnerability lies in the login() function within the /bin/httpd web server, which is a core component of the affected router's firmware.
Technically, the normal authentication system on this device is supposed to verify user credentials through an MD5 mechanism. However, a fallback mechanism was discovered that allows the system to match the password with a hidden configuration named sys.rzadmin.password if standard authentication fails.
If a hacker successfully matches this password, the system will automatically grant administrative access regardless of the username used. This condition allows attackers to log in to the web management panel and freely control the router's operations.
To date, cybersecurity experts advise users to monitor official firmware updates from the manufacturer. This preventive step is crucial to minimize the risk of device exploitation by external parties leveraging this hidden vulnerability.