« Volver al listado

CVE-2026-11405

Estado: AplazadaCrítica (9.8)—

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.

- The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.

A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de backdoor en servidor web expuesto (AV:N, PR:N): autenticación bypass mediante strcmp() plaintext permite acceso sin privilegios a rol admin (T1078.001) y ejecución de comandos posteriores (T1059).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-11405",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-11405",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-08T03:56:43.961536Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "Tenda",
          "product": "firmware",
          "versions": [
            {
              "status": "affected",
              "version": "US_AC6V2.0RTL_V15.03.06.51_multi_T"
            }
          ]
        },
        {
          "vendor": "Tenda",
          "product": "firmware",
          "versions": [
            {
              "status": "affected",
              "version": "US_AC5V1.0RTL_V15.03.06.48_multi_TDE01"
            }
          ]
        },
        {
          "vendor": "Tenda",
          "product": "firmware",
          "versions": [
            {
              "status": "affected",
              "version": "US_AC10V1.0re_V15.03.06.46_multi_TDE01"
            }
          ]
        },
        {
          "vendor": "Tenda",
          "product": "firmware",
          "versions": [
            {
              "status": "affected",
              "version": "US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE"
            }
          ]
        },
        {
          "vendor": "Tenda",
          "product": "firmware",
          "versions": [
            {
              "status": "affected",
              "version": "US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-06T20:16:29.450",
  "references": [
    {
      "url": "https://cwe.mitre.org/data/definitions/912.html",
      "source": "cret@cert.org"
    },
    {
      "url": "https://kb.cert.org/vuls/id/213560",
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/213560",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.\r\n\r\n- The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).\r\n- After normal authentication fails, it calls GetValue(\"sys.rzadmin.password\") to read a backdoor password from the device configuration.\r\n- It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.\r\n\r\nA successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor"
    }
  ],
  "lastModified": "2026-07-08T14:16:54.773",
  "sourceIdentifier": "cret@cert.org"
}