A newly disclosed vulnerability reveals that multiple versions of Tenda firmware contain a hidden authentication backdoor, putting millions of routers, switches, access points, and IP cameras at risk of remote compromise. The CERT/CC advisory VU#213560, published July 8, 2026, confirms that attackers can bypass authentication entirely using hardcoded credentials embedded in the firmware.
Vulnerability Details
The backdoor exists in the authentication mechanism of Tenda's firmware across multiple product lines. Security researchers discovered that submitting a specific hidden parameter sys.rzadmin.password with the value rzadmin grants full administrative access to the device's web interface, effectively bypassing all normal authentication checks.
Key facts:
- CERT/CC ID: VU#213560
- Nature: Hidden authentication backdoor (hardcoded credentials)
- Discovered: July 8, 2026
- Credential: Username not needed, password is
rzadmin(via system config parameter) - Attack vector: Remote, unauthenticated access to device admin interface
- Impact: Complete device takeover, network pivoting, data exfiltration
Impact Assessment
This is not an isolated bug in a single product. The backdoor spans multiple firmware versions across Tenda's entire product lineup:
- Home and business routers (AC10, AC1200, BE12Pro series)
- Wireless access points
- Network switches
- Video surveillance equipment (IP cameras, NVRs)
Tenda is a major player in the networking hardware market, particularly in price-sensitive segments where their devices are widely deployed in homes, small businesses, hotels, and educational institutions. The company was founded in 1999 and operates R&D centers in Shenzhen and Chengdu, with over 1000 employees and 1300+ patents.
The real danger: Because Tenda devices often sit at the network perimeter (as routers and gateways), a successful exploit gives attackers a foothold inside the target network. From there, they can launch lateral movement attacks, intercept traffic, deploy ransomware, or use compromised devices as part of botnets for DDoS campaigns.
Affected Systems
If you own any Tenda networking equipment, you need to check if your device is affected:
- Routers: AC10 series (firmware V16.03.62.09 and earlier), AC1200 W15Ev2, BE12Pro series
- Access Points: Various enterprise and consumer AP models
- Switches: Managed and unmanaged switch lines
- Surveillance: IP cameras and NVRs running Tenda firmware
To check your device: Log into the admin interface and check the firmware version string. If you see V15.x.x.x or V16.x.x.x releases from before July 2026, you are likely vulnerable.
Mitigation and Patching
Until Tenda releases official patches, here is your action plan:
If you use Tenda equipment at home
- Disable remote management immediately. Turn off WAN-side access to the admin interface.
- Change the default admin password even though the backdoor bypasses it. This still helps against other attack vectors.
- Check for firmware updates weekly at tendacn.com/support.
- Consider replacing the device with hardware from vendors with better security track records (MikroTik, Ubiquiti, or open-source firmware like OpenWrt).
If you manage Tenda equipment at an organization
- Inventory all Tenda devices on your network immediately.
- Isolate them on a segmented VLAN with strict firewall rules blocking admin interface access from untrusted networks.
- Monitor for suspicious activity: check logs for unauthorized config changes, unknown admin sessions, or traffic spikes.
- Plan replacement for critical infrastructure devices. For border routers and firewalls, this should be high priority.
- Watch CERT/CC VU#213560 for updates and patch announcements.
Detection
You can detect whether someone has exploited this backdoor by:
- Checking device logs for successful admin logins at unusual times
- Looking for modified configuration files (compare against known-good backups)
- Monitoring for unexpected outbound connections from the device
- Checking if
sys.rzadminrelated entries appear in the device config (viacat /etc/config/*if you have shell access)
Historical Context
This is not Tenda's first security rodeo. In 2022, researcher Olivier Laflamme disclosed 11 vulnerabilities (including 10 CVEs) in Tenda's W15Ev2 AC1200 router after the company failed to respond to six months of responsible disclosure attempts. Those issues included OS command injection, stack buffer overflows, password disclosure, and improper authorization flaws.
The persistent pattern of unpatched vulnerabilities across multiple firmware versions raises serious questions about Tenda's software development lifecycle and security practices. The fact that a hardcoded backdoor credential persists across versions suggests either intentional design or a systemic failure in code review and security testing.
Frequently Asked Questions
Q: Is my home router affected? A: If it is a Tenda-branded router model (AC10, AC1200, BE12Pro, or similar), almost certainly yes. Check the firmware version in the admin panel.
Q: Can attackers exploit this remotely over the internet? A: Yes, if remote management is enabled on the WAN interface. Even without it, an attacker on your local network (including malware on a connected device) can exploit this against the LAN-side admin interface.
Q: Has this been fixed yet? A: As of July 8, 2026, no official patch has been released. Monitor CERT/CC VU#213560 for updates.
Q: Will a factory reset fix this? A: No. The backdoor is in the firmware image itself, not in user-configurable settings. A factory reset does not remove it.
Q: Is it safe to keep using Tenda devices? A: For critical applications (border routers, business gateways), replace them with alternatives from vendors with active security programs. For less critical devices, isolate them on a separate network segment and disable remote management.
Key Takeaways
- Tenda firmware across multiple product lines contains a hidden authentication backdoor
- The credential
rzadmingrants full admin access without any username - Attackers can exploit this remotely if WAN management is enabled
- No official patch is available yet
- Isolate affected devices and disable remote management immediately
- This is a recurring pattern: Tenda had 10+ CVEs in 2022 from unpatched vulnerabilities
- Consider replacing Tenda networking gear with more security-conscious alternatives
Conclusion
The discovery of a hidden authentication backdoor in Tenda firmware is a stark reminder that the security of network infrastructure devices cannot be taken for granted. When the very devices meant to protect your network perimeter harbor deliberate backdoors, the traditional defense-in-depth model breaks down.
For developers and IT administrators, this incident reinforces three key lessons: audit your supply chain, segment your network, and treat all IoT and networking equipment as untrusted until proven otherwise. Until Tenda provides a clear explanation and a comprehensive patch, the safest course of action is to assume Tenda devices on your network are compromised and act accordingly.
Sources: CERT/CC VU#213560, Hacker News Discussion, Boschko.ca Tenda AC1200 Analysis (2022)
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.