Description
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.

- The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).
- After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.
- It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.

A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor
Published: 2026-07-06
Score: 9.8 Critical
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A hidden backdoor authentication path exists in the Tenda firmware web server binary located at /bin/httpd. The login routine first checks if the provided password matches a stored MD5 hash. If that fails, it reads a configuration value sys.rzadmin.password. The routine then performs a direct plaintext comparison against the supplied password, ignoring the username. Any password that matches sys.rzadmin.password results in the creation of an admin-level session, granting the attacker full device control.

Affected Systems

Tenda routers and network devices that run firmware containing the vulnerable /bin/httpd binary. The vendor identifies this product as Tenda firmware, and the vulnerability is present in multiple unspecified firmware releases. Devices running any firmware version that includes the backdoor code are affected.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical vulnerability. The EPSS score of 2% suggests that exploitation is relatively unlikely, and the issue is not listed in the CISA KEV catalog. Nonetheless, an attacker who can reach the device’s management web interface—whether through local access or a remote connection—can supply the sys.rzadmin.password value and immediately acquire administrator rights. The description does not detail the required network port, so it is inferred that the vulnerable interface is reachable on the typical HTTP/HTTPS ports used for web management. The impact is immediate and total, affecting confidentiality, integrity, and availability of the device.

Generated by OpenCVE AI on July 26, 2026 at 20:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched Tenda firmware release that removes the hidden backdoor authentication path and eliminates hard‑coded credentials.
  • If a firmware update cannot be performed immediately, restrict remote access to the web management interface via firewall rules or router settings, allowing only trusted networks.
  • Clear or delete the configuration value sys.rzadmin.password from the device to eliminate the backdoor credential source.
  • Disable the rzadmin account or separate it from the web management login to prevent unauthorized use.
  • Monitor device logs for suspicious authentication activity or usage of the backdoor parameters.

Generated by OpenCVE AI on July 26, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-912

Wed, 22 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-912

Tue, 21 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-912

Fri, 17 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-912

Wed, 15 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-912

Tue, 14 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-912

Mon, 13 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-912

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-912

Fri, 10 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-256
CWE-287

Wed, 08 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-256
CWE-287

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-250
CWE-287

Tue, 07 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-250
CWE-287

Mon, 06 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor
Title Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-08T13:40:24.471Z

Reserved: 2026-06-05T18:12:15.445Z

Link: CVE-2026-11405

cve-icon Vulnrichment

Updated: 2026-07-06T20:37:55.739Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T20:30:03Z

Weaknesses

No weakness.