PulseAugur
EN
LIVE 14:34:01

Tenda routers contain unpatched backdoor, researchers warn

Cybersecurity researchers have discovered a critical authentication backdoor in several Tenda router models, allowing unauthorized administrative access without requiring any password. The vulnerability, tracked as CVE-2026-11405, was disclosed by the CERT Coordination Center (CERT/CC) at Carnegie Mellon University. Despite warnings and attempts to contact the company, Tenda has not yet released a security patch for the affected firmware versions, leaving users exposed to potential network compromise. AI

RANK_REASON Disclosure of a vulnerability in a consumer hardware product.

Read on Mastodon — fosstodon.org →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

Tenda routers contain unpatched backdoor, researchers warn

COVERAGE [2]

  1. Tom's Hardware TIER_1 English(EN) · Etiido Uko ·

    Hidden backdoor in Tenda routers goes unpatched as company ignores warnings from cybersecurity researchers — Chinese company's firmware allows admin access without a password

    CERT/CC has disclosed a critical authentication backdoor affecting multiple Tenda router firmware versions. Tracked as CVE-2026-11405, the flaw grants full administrator access without valid credentials, and no vendor patch is currently available after CERT failed to reach Tenda.

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    Hidden backdoor in Tenda routers goes unpatched as company ignores warnings from cybersecurity researcher… CERT/CC has disclosed a critical authentication backd

    Hidden backdoor in Tenda routers goes unpatched as company ignores warnings from cybersecurity researcher… CERT/CC has disclosed a critical authentication backdoor affecting multiple Tenda router firmware versions. Tracked as CVE-2026-11405, the flaw grants full administrator acc…