In brief: Tenda devices contain an undocumented backdoor (CVE-2026-11405) without an available patch that grants admin rights regardless of username.
The CERT Coordination Center warns of a critical backdoor (CVE-2026-11405) in Tenda routers and network devices that grants attackers admin rights. A security update from the manufacturer is not available.
The vulnerability sits in the login function of the webserver binary code of affected Tenda devices. The authentication mechanism attempts, when a regular login fails, to read a password value stored in the device configuration. The system compares the user password in plaintext with this value and grants administrative access on match. Crucially: the associated username is not validated. Any arbitrary username succeeds as long as the backdoor password is correct. This mechanism is neither documented nor detectable through administrative interfaces.
For a CISO, this presents significant risks at the network perimeter. A successful attack enables actors to modify device configurations and network settings as well as to completely disable security functions. This can lead to compromise of the local network. The CERT/CC was unable to achieve coordination with Tenda to address the issue. Official patches are not available to date.
As interim measures, the CERT/CC recommends disabling remote management of affected devices and changing the default LAN IP address. This reduces the risk that malware scanners automatically detect and exploit the devices.
In parallel, the CERT/CC warns of CVE-2026-13753 in HP Deskjet printers (up to firmware TBP1CN2612AR). Here, a missing authorization check enables unauthenticated GET requests to access backend API endpoints. These return administrative data in plaintext: Wi-Fi Direct SSID, passphrases, serial numbers and admin password status. For this vulnerability as well, no patch is available.
Source: www.it-daily.net · Published 10 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.