Hidden Authentication Backdoor (CVE‑2026‑11405) Grants Admin Access in Tenda Router Firmware
What Happened — A hidden authentication backdoor was discovered in several Tenda Wi‑Fi router firmware versions (CVE‑2026‑11405). The backdoor bypasses normal MD5‑based login: if a supplied password matches an undocumented “sys.rzadmin.password” value, the router grants full administrative access regardless of the username. The flaw is undocumented, unpatched, and the vendor could not be reached for remediation.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a classic failure of logical access‑control design – a scenario SOC 2 CC6.1 expects organizations to enforce least‑privilege and documented authentication mechanisms.
- Continuous‑compliance programs must capture evidence that network‑device configurations (firmware version, admin passwords, remote‑management settings) are monitored and that undocumented backdoors are identified and mitigated.
- Verisq’s SOC 2 Access‑Controls capability helps map device‑level access controls to audit criteria and provides automated evidence collection for firmware and configuration drift.
Who Is Affected — Telecommunications providers, small‑to‑medium businesses, and any organization that deploys Tenda routers in office or branch locations.
Recommended Actions
- Inventory all Tenda devices and record firmware versions.
- Disable the remote web‑management interface until a patch is available.
- Change the default LAN IP range to limit discovery by automated scanners.
- Incorporate router firmware version and configuration checks into your continuous control monitoring framework (SOC 2 CC6.1).
- Document the remediation steps as audit evidence. Source: BleepingComputer
Technical Notes
- Attack vector: exploitation of an undocumented authentication routine in
/bin/httpd(VULNERABILITY_EXPLOIT). - CVE: CVE‑2026‑11405 (no public CVSS score yet).
- Affected firmware: FH1201, W15E, AC10, AC5, AC6 V2 (various version numbers).
- Potential impact: full admin control of the router, enabling network re‑configuration, disabling security features, and lateral movement. Source: CERT/CC Bulletin