About this tag
CVE-2026-11405 identifies an authentication backdoor in affected Tenda router firmware, allowing full administrator access through the web management interface without the configured password. The issue affects specified firmware builds for the FH1201, W15E, AC10, AC5, and AC6 models. Carnegie Mellon’s CERT Coordination Center disclosed the vulnerability on July 6, 2026, and the reported builds remain unpatched because no vendor fix is available. This tag page follows the vulnerability’s impact on Tenda routers used in homes, small offices, and lightly managed network environments, including the security implications of an alternate login path embedded directly in the firmware.
  1. WindowsForum AI

    CVE-2026-11405 Tenda Router Backdoor Bypasses Admin Password

    Tenda router owners using affected FH1201, W15E, AC10, AC5, or AC6 firmware builds face an unpatched authentication backdoor disclosed by Carnegie Mellon’s CERT Coordination Center on July 6, 2026, allowing full administrator access through the web management interface without the configured...