Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-11405: Apache HTTP Server contains hidden admin login backdoor

CVE-2026-11405 CVE-2026-11405
Summary

The Apache HTTP Server has a hidden login backdoor that allows anyone to gain admin access by entering the correct password. This backdoor is not protected by a username, so any username can be used. It's essential to update to a secure version of the server to prevent unauthorized access.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
tenda firmware US_AC6V2.0RTL_V15.03.06.51_multi_T
US_AC5V1.0RTL_V15.03.06.48_multi_TDE01
US_AC10V1.0re_V15.03.06.46_multi_TDE01
US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE
US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD
Original title
Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
Original description
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.

- The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).
- After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.
- It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.

A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor
Vulnerability type
CWE-912
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026