Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday.

The CERT Coordination Center (CERT/CC) has warned of a hidden admin backdoor in several versions of firmware released by Chinese network device manufacturer Tenda. The backdoor, tracked as CVE-2026-11405, allows an attacker to bypass the password verification process and gain administrative access to the devices' web management interfaces. CERT/CC described the vulnerability as very severe and urged Tenda to take immediate action to fix it. Tenda has begun working on a patch to address the issue. CERT/CC chose not to disclose the vulnerability publicly, citing the potential for attackers to exploit it before a patch is available. Instead, they notified Tenda and are working with the company to resolve the issue.