US CERT/CC just issued a security alert: multiple Tenda router firmware versions have a hidden backdoor-style authentication flaw, tracked as CVE-2026-11405. The scariest part? Attackers may bypass normal username/password checks and still gain **admin access** to the router’s web management interface. Affected models reportedly include FH1201, W15E, AC10, AC5, and AC6. As of the announcement, there’s no official patch yet—so users need to reduce exposure immediately. CERT/CC reports the weakness sits in the web login logic. If standard MD5-based authentication fails, the router can switch to an “alternative password” mechanism. If an attacker supplies the firmware-configured fallback password—even with the wrong username—the system may still grant entry as an administrator. Worse: Tenda allegedly never documented this alternative login path in public materials or the admin UI, making it easy for everyday users to miss the risk. For now, CERT/CC recommends disabling remote web management so the admin panel isn’t reachable from the public internet, and monitoring for firmware updates. #CyberSecurity #RouterSecurity #CVE #Vulnerability #NetworkSafety #CERTCC
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论