Particle.news

Hidden Admin Backdoor Found in Tenda Router Firmware, Patch Unavailable

CERT/CC says the vulnerability is built into the router web server binary and advises disabling remote web management as a stopgap.

Overview

  • CERT/CC published an advisory after an anonymous researcher reported the flaw, with the advisory and follow-up reporting appearing on Monday, July 6 and through July 7, 2026.
  • The backdoor lives in the /bin/httpd login() function and checks a hidden configuration value GetValue("sys.rzadmin.password") using a plaintext strcmp to grant role=2 administrative access.
  • The mechanism accepts any username when paired with the hidden password so an attacker who supplies that value can create an admin session without knowing the device's configured credentials.
  • CERT/CC lists multiple affected firmware builds across consumer models including FH1201, W15E, AC10, AC5, and AC6 and warns that the code is baked into the firmware binary so resets or normal config changes do not remove it.
  • No vendor patch is available and CERT/CC says it could not coordinate a fix with Tenda, so users should disable remote management, restrict LAN exposure or replace vulnerable devices to prevent full-device takeover and downstream network compromise.