Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-11405: Apache HTTP Server contains hidden admin login backdoor
CVE-2026-11405
CVE-2026-11405
Summary
The Apache HTTP Server has a hidden login backdoor that allows anyone to gain admin access by entering the correct password. This backdoor is not protected by a username, so any username can be used. It's essential to update to a secure version of the server to prevent unauthorized access.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | firmware |
US_AC6V2.0RTL_V15.03.06.51_multi_T US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD |
Original title
Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
Original description
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.
- The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).
- After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.
- It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.
A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor
- The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).
- After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.
- It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.
A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor
Vulnerability type
CWE-912
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026