PT-2026-55969 · Tenda · Ac5+4

CVE-2026-11405

·

Published

2026-07-06

·

Updated

2026-07-20

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda firmware versions US FH1201V1.0BR V1.2.0.14(408) EN TD Tenda firmware versions US W15EV1.0br V15.11.0.5(1068 1567 841) EN TDE Tenda firmware versions US AC10V1.0re V15.03.06.46 multi TDE01 Tenda firmware versions US AC5V1.0RTL V15.03.06.48 multi TDE01 Tenda firmware versions US AC6V2.0RTL V15.03.06.51 multi T
Description A hidden authentication backdoor exists in the /bin/httpd web server binary within the login() function. While the function initially uses a standard authentication path with MD5 hash-based password verification via prod encode64(), PasswordToMd5(), and check rand key(), a secondary execution path is triggered if the initial authentication fails. This secondary path calls the GetValue() function to retrieve a backdoor password associated with the sys.rzadmin.password variable from the device configuration. The system then performs a direct strcmp() comparison between this stored plaintext value and the password provided by the user. If they match, the system grants administrative access (role=2) and creates a valid session. The username is not validated during this process, meaning any username paired with the backdoor password grants full administrative control over the web management interface. This allows remote attackers to modify configurations, disable security features, and use the device as a pivot point for lateral movement within the local network. Real-world incidents have been reported where attackers exploited this backdoor for internal reconnaissance and establishing command-and-control channels.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Disable remote management on the device. Change the default LAN IP address to reduce exposure to automated scanners. Restrict access to the web management interface from the local network.

Exploit

Hidden Functionality

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09385
CVE-2026-11405

Affected Products

Ac10
Ac5
Ac6
Fh1201
W15E