CERT/CC has identified a hidden backdoor in multiple Tenda router firmware versions. This backdoor allows unauthorized administrative access to the devices' web interfaces.

A significant security vulnerability has been discovered in the firmware of several Tenda router models, potentially exposing users to unauthorized administrative access. The CERT Coordination Center (CERT/CC) has issued a warning about this hidden backdoor, which allows attackers to bypass normal authentication procedures and gain control over the router's web interface.
The vulnerability lies within the firmware itself, meaning that even if users have set strong passwords for their router's administrative login, this backdoor can still be exploited. This bypass mechanism could allow an attacker to access and modify critical network settings, potentially redirecting user traffic, disabling security features, or even using the router as a pivot point to attack other devices on the network.
While the specific firmware versions affected have not been detailed in the initial reports, the CERT/CC's alert suggests that multiple Tenda router models are susceptible. This broad potential impact underscores the importance of staying informed about firmware updates and security advisories from device manufacturers.
The nature of the backdoor implies a serious risk to both home and small business users who rely on Tenda routers for their internet connectivity and network security. Unauthorized access to router settings can have far-reaching consequences, including data interception, denial-of-service attacks, and the compromise of sensitive information transmitted over the network.
Details regarding how the backdoor is implemented or triggered are not yet publicly available. However, the existence of such a hidden mechanism raises questions about the security development lifecycle and testing processes employed by the manufacturer.
Users of Tenda routers are strongly advised to remain vigilant and seek out any official security advisories or firmware updates released by Tenda. Applying the latest firmware is a critical step in patching known vulnerabilities and maintaining the security posture of network devices.
In the absence of specific patch information, general best practices for router security remain paramount. This includes regularly changing default administrative passwords, disabling remote administration features if not strictly necessary, and ensuring that the router's firmware is kept up-to-date.
The CERT/CC's alert serves as a crucial warning to the cybersecurity community and Tenda device owners. Further information regarding the specific affected models and mitigation steps is expected to be released as the investigation progresses.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed