← 返回日报
精读 预计 2 分钟

Tenda firmware (multiple versions) contains hidden authentication backdoor

摘要

CERT 报告概述:Tenda 固件多版本存在未记录的认证后门,在 /bin/httpd 的 login () 函数中,若常规 MD5 验证失败,会通过 GetValue ("sys.rzadmin.password") 获取配置备用密码,并用 direct strcmp () 明文比对;匹配成功后授予 role = 2 管理员权限并创建会话。受影响版本包括 US FH1201V1.0BR、US W15EV1.0br、US AC10V1.0re、US AC5V1.0RTL、US AC6V2.0RTL 等。影响为攻击者可绕过管理员密码获设备完整控制。解决方案仅为临时缓解:禁用远程管理、更改默认 LAN IP。报告日期 2026-07-06,无厂商补丁。

荐读理由

报告明确指出登录函数中未文档化的后门机制,通过配置文件获取备用密码并进行直接字符串比较绕过验证,用户在场检验下能立即验证该机制如何使攻击者无需凭证获得管理员访问,进而指导在部署 AI 相关网络设备时评估类似未记录机制的潜在风险

原文

Overview

Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials.

Affected Versions:

  • US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD
  • US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE
  • US_AC10V1.0re_V15.03.06.46_multi_TDE01
  • US_AC5V1.0RTL_V15.03.06.48_multi_TDE01
  • US_AC6V2.0RTL_V15.03.06.51_multi_T

Description

Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. Most of these devices include web-based interfaces that allow users to perform configuration and management operations, which are protected by username/password authentication to prevent unauthorized modifications.

The web server binary /bin/httpd contains an undocumented backdoor authentication mechanism in the login() function. Initially, the function follows a normal authentication path using MD5-based password verification. However, if authentication fails, the function invokes GetValue("sys.rzadmin.password") to retrieve an alternate password value from the device configuration. It then performs a direct strcmp() comparison in plaintext between the user-supplied password and the configuration-stored value. A successful match grants role=2 admin-level access and creates a valid session.

The associated username is not validated, so any provided username will succeed when paired with the backdoor password. This backdoor authentication mechanism is not documented or visible through any administrative interface.

Impact

Successful exploitation grants full administrative access to the device's web interface, regardless of the configured administrator account credentials. With administrative control, an attacker can reconfigure the device, alter network settings, and disable security features, enabling broader compromise of the local network.

Solution

Unfortunately, we were unable to reach the vendor to coordinate this vulnerability. Since a patch is unavailable, we can only offer mitigation strategies. The following workarounds can help mitigate this vulnerability's impact until a fixed version is released:

Disable remote management on your device If your device supports remote web management, disable it. Disabling this feature prevents attackers on external networks from accessing your device’s administrative dashboard over the internet.

Restrict local network exposure Changing the default LAN IP address may reduce opportunistic discovery by automated scanners that target known default IP ranges. Note that this measure does not prevent deliberate or targeted network scanning.

Acknowledgements

Thanks to the reporter who wishes to remain anonymous. This document was written by Bob Kemerer.

Vendor Information

213560

Expand all

Tenda Unknown

Notified: 2026-05-19 Updated: 2026-07-06

CVE-2026-11405 Unknown

Vendor Statement

We have not received a statement from the vendor.

References

Other Information

CVE IDs: CVE-2026-11405
**API URL: ** VINCE JSON | CSAF
Date Public: 2026-07-06
Date First Published: 2026-07-06
**Date Last Updated: ** 2026-07-06 19:22 UTC
**Document Revision: ** 1
Hacker News · 168 赞 · 48 评 讨论 → 阅读原文 →

这条对你有帮助吗?