9.8 CVE-2026-11405
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.
- The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).
- After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.
- It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.
A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor
https://nvd.nist.gov/vuln/detail/CVE-2026-11405
Categories
No category defined
References
af854a3a-2127-422b-91ae-364da2661108
cret@cert.org
AFFECTED (from MITRE)
| Vendor |
Product |
Versions |
| Tenda |
firmware |
- US_AC6V2.0RTL_V15.03.06.51_multi_T [affected]
|
| Tenda |
firmware |
- US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 [affected]
|
| Tenda |
firmware |
- US_AC10V1.0re_V15.03.06.46_multi_TDE01 [affected]
|
| Tenda |
firmware |
- US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE [affected]
|
| Tenda |
firmware |
- US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD [affected]
|
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. |
CPE
REMEDIATION
EXPLOITS
Exploit-db.com
| id |
description |
date |
|
| No known exploits |
POC Github
Other Nist (github, ...)
CAPEC
Common Attack Pattern Enumerations and Classifications
| id |
description |
severity |
| No entry |
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.
Discover this offer