CVE-2026-11405: Multiple Tenda Routers Have an Admin Backdoor

Last Updated: 2026-07-08T15:51:19Z

CVSSv3: None yet

Multiple versions of Tenda firmware have a backdoor in remote administration login, allowing anyone to access configuration of the device.

Affected Versions:

  • US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD
  • US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE
  • US_AC10V1.0re_V15.03.06.46_multi_TDE01
  • US_AC5V1.0RTL_V15.03.06.48_multi_TDE01
  • US_AC6V2.0RTL_V15.03.06.51_multi_T

No patch is currently available.

We recommend burning your Tenda devices in the nearest volcano disabling remote administration and reviewing all access/activity logs.

UPDATE: Per Will Dormann, this may be bogus. He has found few instances of the backdoor in question in his research, and where he has, they are not in the listed firmware versions.

Image Source

Inexpensive brick and pavers path entry, backdoor, $1 dollar each (Home Depot), total cost $4, Seattle, Washington, USA” by Wonderlane is licensed under CC BY 2.0. Changes made by IFIN.

1 Like