Hidden Admin Backdoor Found in Tenda Router Firmware, CERT/CC Warns
CVE-2026-11405 lets an attacker skip the password check entirely and seize full administrative control of affected Tenda routers through the web interface.

Key points
- The CERT Coordination Center (CERT/CC) warned Monday that several Tenda firmware versions contain a hidden authentication backdoor.
- The flaw, CVE-2026-11405, lets an attacker bypass the login process on the router's web management page.
- Once inside, an attacker holds full administrator rights and can redirect traffic, alter settings, or install persistent malicious code.
- Home users and small businesses on affected Tenda hardware should check the vendor's support page for a firmware update and block the admin page from the internet in the meantime.
A U.S. Government-funded security group has warned that several Tenda router models ship with a secret way in.
The CERT Coordination Center (CERT/CC), a vulnerability clearinghouse run out of Carnegie Mellon University, said Monday that multiple firmware releases from Chinese networking vendor Tenda include an undocumented authentication backdoor. That's a hidden shortcut baked into the software that lets someone log in as administrator without knowing the real password. The issue is tracked as CVE-2026-11405 and sits in the web interface, the browser page used to configure the router.
What can an attacker actually do with this?
They can take full control. CERT/CC says the flaw lets an attacker bypass the password check and reach the administrative panel, the same view the device's owner sees when changing Wi-Fi settings or pushing a firmware update.
From there, the options are ugly. An attacker can alter DNS settings (the phonebook the router uses to look up websites) and silently redirect users to fake banking or email pages. They can expose the network to further intrusion or plant code that survives reboots. Routers hijacked this way are also a favourite building block for botnets, large groups of infected devices used to hit other targets.
The advisory, first reported by The Hacker News, doesn't tie the backdoor to any confirmed attack in the wild. But an undocumented admin bypass in consumer networking gear is exactly what criminal groups and state-linked crews scan for at scale, usually within days of disclosure.
Who is affected?
CERT/CC says the backdoor is present in several Tenda firmware versions. The coordinator's advisory is the primary source for the exact model and firmware list; defenders should treat that list, not summaries, as authoritative. At time of writing, Tenda hadn't published its own security advisory acknowledging the flaw, which isn't unusual for this vendor.
Tenda gear sells widely to home users and small businesses, often as budget Wi-Fi routers and range extenders. That means the people most exposed are the least likely to be watching CVE feeds.
Should you worry?
Yes, if you're running Tenda hardware. Backdoors that ship from the factory, whether left in by mistake or by design, rarely turn out to be one-offs. We first covered Tenda on 7 July 2026, and this CVE is a sharper finding than anything we've reported on this vendor before.
What should router owners do now?
Check whether your router is a Tenda model and, if so, look on the vendor's support page for a firmware update matching your exact model number. Install it when one is available.
Make sure the admin page isn't reachable from the wider internet. Most home routers have a setting called "remote management" or "WAN admin access". Turn it off. This doesn't fix the bug, but it forces an attacker to already be on your local network to exploit it.
Change the admin password to something long and unique, and change the Wi-Fi password too. Neither stops CVE-2026-11405 on its own, but both raise the cost of everything else an attacker might try.
If you run a small business on consumer-grade Tenda kit, this is a reasonable moment to price up a replacement from a vendor with a clearer track record on patching.



