LIVE · cybersecurity feed
Live wire
CVE-2026-11405critical

Tenda Firmware Vulnerability Allows Unauthenticated Admin Access

A critical backdoor vulnerability has been discovered in Tenda device firmware, identified as CVE-2026-11405. This flaw enables unauthenticated attackers to gain administrative control over affected devices by accessing their web management interface. The vulnerability remains unpatched, posing a significant risk to users.

zeroday.news · 23d ago

A critical vulnerability has been identified in the firmware of Tenda devices, allowing attackers to gain administrative access without authentication. The flaw, tracked as CVE-2026-11405, affects the web management interface of the affected devices.

This vulnerability means that an unauthenticated attacker could potentially take full control of a Tenda device by exploiting this weakness. As of the latest reports, Tenda has not yet released a patch to address this security issue, leaving users exposed to potential compromise.

The discovery highlights a significant security risk for users of Tenda networking equipment. The ability for an attacker to gain administrative privileges remotely and without needing any credentials could lead to a wide range of malicious activities, including network surveillance, data interception, or the deployment of further malware.

While the specific Tenda product lines or firmware versions affected by CVE-2026-11405 have not been widely detailed in initial reports, the existence of such a backdoor in the administrative interface is a serious concern. Users are advised to remain vigilant for any security advisories or firmware updates from Tenda.

The nature of the vulnerability suggests a potential oversight in the device's security implementation, allowing for bypass of authentication mechanisms. This could be exploited through specially crafted network requests directed at the device's web interface.

Without a patch, the recommended course of action for users is to implement additional network security measures where possible. This might include restricting access to the device's management interface from untrusted networks or monitoring network traffic for suspicious activity targeting Tenda devices.

The ongoing lack of a patch from Tenda means that the risk associated with CVE-2026-11405 persists. Further details regarding the technical exploitation of the vulnerability and the full scope of affected devices are expected as security researchers continue to analyze the issue.

This situation underscores the importance of regular firmware updates and the need for manufacturers to prioritize robust security practices throughout the product development lifecycle. Users of Tenda devices should actively check for any future communications from the vendor regarding this critical vulnerability.

iotfirmwarevulnerabilitybackdoortenda
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]