
Security researchers working with CERT/CC have discovered a hidden backdoor buried inside the firmware of Tenda home routers. The vulnerability, tracked as CVE-2026-11405, allows anyone on your network to log into your router’s admin panel without knowing the real password. An attacker who gets in can change your Wi-Fi settings, redirect your internet traffic, disable firewall rules, or use your router as a base for attacking other devices on your network.
The backdoor works because the router’s login software secretly stores a second, undisclosed password in the device’s configuration. If the normal password check fails, the router quietly falls back to this hidden credential — letting an attacker in through a back door the manufacturer never disclosed. Tenda has not released a patch as of this writing, and CERT/CC has urged users to take precautions in the meantime.
How to check if you’re affected
Affected devices include Tenda home routers running the vulnerable firmware. To check your device: open a browser and go to your router’s admin page (usually 192.168.0.1 or 192.168.1.1), then look at the status or system page for the current firmware version. Cross-reference that against any available update on Tenda’s official support site. Until CVE-2026-11405 is patched, you can reduce your exposure by disabling remote management in the router settings and ensuring your Wi-Fi password is long and unique.
