Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Backdoor Found in Common Router Software Allowing Easy Admin Access

A serious security flaw has been found in the software of some Tenda routers. It allows anyone who knows a hidden password stored in the device to gain full administrative control without normal login checks. This could let attackers take over your network equipment.

09 July 2026

Reference: CVE-2026-11405

1. What is being reported?

Researchers discovered a secret backdoor in the login system of certain Tenda router software. Normally, routers check usernames and passwords securely. But this backdoor bypasses normal checks by using a special password stored in the router’s settings. If someone knows this password, they can log in as an admin without restrictions.

2. What this means in plain English

If your business uses one of these routers and it has not been updated, an attacker could gain full control over your network device. This means they could change settings, intercept data, or disrupt your internet connection. It’s a serious risk because the backdoor works regardless of the username used.

3. Could this affect a small business?

Small businesses using Tenda routers with this vulnerable software could be affected, especially if the router firmware has not been updated recently. If you use other brands or have professional network equipment, you are less likely to be affected. Check with your IT provider to confirm.

4. What to do now

  • Check if your router is a Tenda model and identify its firmware version.
  • Contact your router supplier or IT provider to confirm if your device is vulnerable.
  • Apply any available firmware updates or patches from Tenda immediately.
  • If no update is available, consider replacing the router or isolating it from sensitive parts of your network.

5. Ask your IT provider

Can you confirm if our Tenda router is affected by the CVE-2026-11405 backdoor vulnerability and advise on the necessary updates or replacements?

6. Bottom line

Make sure your router’s software is up to date to prevent attackers from easily gaining admin access through a hidden backdoor.

Information based on CISA KEV, NVD, and reputable security news reports.

Back to Vulnerability Briefs