Summary
CERT/CC has disclosed a critical security flaw, CVE-2026-11405, in multiple Tenda router families, allowing attackers full admin access via a hardcoded backdoor credential. Tenda has not yet responded, and users are advised to disable remote web management as a partial mitigation.