- CERT/CC discloses CVE‑2026‑11405, a critical 9.8/10 flaw in multiple Tenda router families caused by a hardcoded backdoor credential
- Attackers can bypass normal login checks and gain full admin access with the hidden password, regardless of configured username or password
- Tenda has not responded; CERT/CC advises disabling remote web management and limiting local exposure, though these are only partial mitigations
Multiple Tenda router families carry a critical vulnerability that allows malicious actors to log in with admin privileges without knowing the credentials, experts have found.