Network Security Tenda routers have unpatched backdoor vulnerability, CERT/CC warns July 9, 2026 Share By SC Staff (Adobe Stock) Multiple Tenda router firmware versions contain an undocumented authentication backdoor that allows attackers to bypass login and gain full administrative access, according to a recent report by Security Affairs. The vulnerability, tracked as CVE-2026-11405, resides in the login function of the router's web server binary. If the normal password check fails, the system attempts to retrieve a hidden password from the device configuration and compares it directly with the user-supplied password. Any username can be used with this backdoor password to achieve administrative privileges, completely bypassing the owner's set credentials. Affected models include the FH1201, W15E, AC10, AC5, and AC6. Successful exploitation grants attackers full control, enabling them to redirect traffic, disable security features, or use the router as a pivot point into the connected network. The backdoor is hardcoded into the firmware and cannot be disabled through the management interface. CERT/CC recommends disabling remote management and changing the default LAN IP address as interim mitigations until Tenda releases a patch, though the vendor has not yet responded. Source: Security Affairs An In-Depth Guide to Network Security Get essential knowledge and practical strategies to fortify your network security. Learn More SC Staff Related Network Security WireVPN linked to long-running operation using victims’ devices as proxy network SC Staff July 9, 2026 Infoblox researchers uncovered the operation after analyzing a malicious 7-Zip installer. They found over 230 related domains linked through various infrastructure indicators. Network Security FortiBleed campaign steals 110M credentials from FortiGate targets Laura French June 24, 2026 A tool called FortigateSniffer abuses a diagnostic utility to continuously monitor network traffic. Network Security Cloudflare blocked 38.5 billion cyberattacks against civil society organizations SC Staff June 18, 2026 The majority of attacks against these organizations were DDoS floods, with a notable difference in duration compared to attacks on Cloudflare's broader customer base. Related Events Cybercast How to transform your SOC through XDR and MDR On-Demand Event Cybercast AI for network security: Problems and solutions On-Demand Event Virtual Conference Fortifying the Foundation: Tackling Evolving Challenges in Network Security On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms ACK Piggybacking Bridge Broadcast Cache Poisoning Call Admission Control (CAC) Cell Circuit Switched Network Decapsulation Domain Domain Name You can skip this ad in 5 seconds