Hidden Authentication Flaw Exposes Several Tenda Router Firmware Versions to Admin Takeover

news
Hidden Authentication Flaw Exposes Several Tenda Router Firmware Versions to Admin Takeover

A serious security flaw has been discovered in several versions of Tenda router firmware. The issue can allow an attacker to bypass the normal login process and gain full administrative access to the router’s web management interface.

The vulnerability is tracked as CVE 2026 11405. It affects the web server component built into the router firmware. When a normal login attempt fails, the software checks the entered password against an undocumented password stored in the device configuration. If the values match, access is granted without requiring a valid administrator username or the owner’s normal password.

Administrative access would allow an attacker to change important router settings. This could include modifying DNS servers, redirecting traffic, changing wireless settings, creating new accounts or blocking the owner from accessing the device.

The flaw is especially dangerous when remote web management is enabled because the router’s administration page may be reachable from the internet. An attacker on the same local network could also attempt to exploit the issue.

Security detailConfirmed information
VulnerabilityCVE 2026 11405
Main problemUndocumented authentication mechanism
Access gainedFull router administration
Possible attack locationLocal network or internet when remote management is enabled
Permanent correctionFirmware update from the manufacturer
Immediate protectionDisable remote administration and restrict management access

Several firmware releases are confirmed to contain the flaw

The investigation identified six affected firmware packages associated with several Tenda product families. Confirmed firmware includes versions used by the FH1201, W15E, AC10, AC5 and AC6 lines.

This does not automatically mean that every router carrying one of those product names is vulnerable. Hardware revisions and regional firmware packages can differ even when the model number appears similar.

Owners should open the router administration page and compare the complete installed firmware number with the versions listed in the relevant security notice. The model name alone is not enough to determine whether a particular device is affected.

There is currently no confirmed evidence that every Tenda router contains the same mechanism. Claims that millions of devices are exposed should therefore be treated cautiously until the affected product range is documented more fully.

The undocumented code is described as a backdoor because it provides an alternative path around standard authentication. However, the available technical findings do not establish why the mechanism was added or who was responsible for it. Speculation about government involvement or deliberate surveillance is not supported by the disclosed evidence.

Router owners should disable remote administration immediately

Anyone using a potentially affected Tenda router should first disable remote administration, remote web management and other settings that expose the control panel through the internet.

The management interface should be available only from the local network. Access should preferably be limited to a wired connection or a trusted device where the router provides that option.

Changing the normal administrator password is still sensible, but it does not remove this particular vulnerability because the undocumented authentication path operates separately from the standard password check.

Owners should also install the latest official firmware available for their exact model and hardware revision. Firmware intended for a similar model should never be installed because an incorrect package can make the router unusable.

Until corrected firmware is available, a vulnerable router should not be relied upon for sensitive networks. Replacing the device may be the safest option when remote management cannot be disabled or when the router no longer receives security updates.

Router owners should not attempt to verify the flaw by entering a publicly reported backdoor password. Testing could expose sensitive credentials, create legal concerns on equipment that is not personally owned and provide little assurance that the device is otherwise secure.

The vulnerability shows why router firmware requires the same attention as software on computers and phones. A compromised router sits between every connected device and the internet, giving an attacker a valuable position from which to observe or manipulate network traffic.

Discover: News

Discussion (0)

Be the first to comment.