Vulnerabilities

Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices

Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device’s web management interface.

Router vulnerabilities

A security researcher has discovered an undocumented backdoor in multiple Tenda firmware versions that provides attackers with administrative access to a device’s web management interface.

The security hole appears to affect Tenda routers, switches, and other types of networking devices.

Tracked as CVE-2026-11405, the vulnerable code was found in the login function of the web server binary and can be abused for authentication bypass, warns the CERT Coordination Center (CERT/CC) at Carnegie Mellon University.

The issue exists because, when authentication fails, the login mechanism attempts to retrieve a password value stored in the device’s configuration.

Next, the mechanism checks only the user-supplied password against the value stored in the configuration, in plaintext, and grants administrative access upon a successful match.

“The associated username is not validated, so any provided username will succeed when paired with the backdoor password. This backdoor authentication mechanism is not documented or visible through any administrative interface,” CERT/CC explains.

Advertisement. Scroll to continue reading.

Successful exploitation of the security defect provides an attacker with the ability to modify device configurations and network settings, and to disable security features, which could lead to local network compromise.

CERT/CC says it was unable to coordinate with the vendor to disclose the security defect, and no patch has been released for it.

Users are advised to disable the remote web management of their devices to prevent unauthorized external access and to change the default LAN IP address to reduce the risk of discovery by automated scanners.

On Tuesday, CERT/CC also disclosed a missing authorization vulnerability in HP Deskjet 2800 series printers running firmware versions up to TBP1CN2612AR. The flaw has not been patched and is tracked as CVE-2026-13753.

An attacker can send GET requests to multiple backend API endpoints that, without authentication or session state validation, return admin configuration data such as Wi-Fi Direct SSID, plaintext passphrase, unique printer serial numbers, service IDs, and administrative password state details.

“This vulnerability allows unauthenticated access to the printer’s webserver API endpoints, exposing Wi-Fi credentials, management configuration details, and sensitive security data normally restricted to administrative users,” CERT/CC explains.

Related: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws

Related: Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection

Related: Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Related: ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access

Related Content

Vulnerabilities

The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Vulnerabilities

The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.

Vulnerabilities

Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.

Vulnerabilities

The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges.

Vulnerabilities

The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.

Vulnerabilities

The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.

Vulnerabilities

Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version