CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

A critical vulnerability has been discovered in Tenda router firmware, allowing attackers to remotely access and control affected devices with administrative privileges without leaving any trace of their activity. The CERT/CC, a leading cybersecurity authority, issued a warning about this hidden backdoor, which could have far-reaching implications for internet users.

The issue stems from a flaw in the way Tenda routers process certain network requests, enabling attackers to inject malicious code and gain administrator access to devices. This is made possible by a vulnerability in the firmware’s handling of HTTP requests, specifically when dealing with specific packets containing a specific combination of IP addresses and packet lengths. Once exploited, an attacker can manipulate the device’s configuration, modify its settings, or even use it as a jumping point for further attacks on other networks.

Tenda routers are commonly used by small businesses and residential users around the world. The affected firmware versions span several models, with an estimated hundreds of thousands of devices potentially vulnerable to this exploit. Users who have not updated their router’s firmware in recent months are particularly at risk, as new security patches were released in June to address similar vulnerabilities.

The CERT/CC warning highlights the growing threat posed by AI-driven vulnerability discovery tools. These AI models can rapidly scan large codebases for potential weaknesses and report them back to researchers or exploit them themselves if they fall into malicious hands. This vulnerability was likely discovered using such a tool, which underscores the importance of keeping software up-to-date and regularly scanning systems for vulnerabilities.

While this specific issue is limited to Tenda routers, it serves as a reminder that any device with network connectivity can be vulnerable to similar attacks. Users should remain vigilant about updating their devices’ firmware and software, as well as monitoring their networks for suspicious activity. Furthermore, organizations should implement robust cybersecurity measures, including regular vulnerability assessments and penetration testing, to stay ahead of emerging threats.

To mitigate this risk, users are advised to immediately update their Tenda router’s firmware to the latest version available on the manufacturer’s website. It is also crucial to change any default login credentials for remote access to ensure that even if an attacker gains access to the device, they will not be able to use administrator privileges without a valid password.


Source: The Hacker News — 2026-07-07