Hidden Backdoor in Tenda Firmware Grants Full Admin Access Without Password

Tenda firmware (multiple versions) contains hidden authentication backdoor

I uncovered a critical flaw in several Tenda firmware versions where a hidden backdoor bypasses standard password checks. Attackers can exploit this to gain full administrative control over routers and access points simply by using a specific secret password, regardless of the configured username. Since the vendor remains unreachable, users must disable remote management to protect their networks.

The associated username is not validated, so any provided username will succeed when paired with the backdoor password.
  1. greyface-

    The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does:

    https://boschko.ca/tenda_ac1200_router/

    Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.

  2. fusslo

    > Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment.

    I was unfamiliar with Tenda.

    > Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile )

    Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have no idea if Tenda does this, I've just seen it previously. Specifically with security cameras)

    I wish the authors provided some method for checking this vulnerability other than fw version. It seems like Tenda could just change the password and say "yep! all safe now"

  3. pbasista

    > The associated username is not validated, so any provided username will succeed when paired with the backdoor password.

    Great. I am really wondering why should the customers trust these manufacturers.

    At this point I would not use any router with vendor-provided black box firmware. Full stop.

    I would always install OpenWRT or something similar on it before using it.

    And if that is not possible for whatever reason, I would not even think about buying such a device.

  4. Havoc

    The consistency with which networking hardware companies produce such garbage is crazy.

    And it’s always amateur hour backdoors somehow. If it was something sophisticated they might get a pass on „ok some security agency made them do it probably“

  5. Fabricio20

    Oh this is amazing! I have a few of their cube routers sitting around and I always hated how app-locked their firmware was when it really is just a wifi repeater with a few extras (mesh) on top. Root access will do wonders to bypassing the app now (and also disabling their ping-for-green-light mechanism which spams the network with a constant dns resolution to microsoft.com lol).

    Also honest take this looks less like a "backdoor" (implies malicious - this is a link to a CVE after all) and more like a developer access credential/default credential that was burned into the firmware (i'd imagine the code remains but on a production run they randomize the key so its non-guessable but then you get lazy and dont run that extra step and this slips in/you burn the bare firmware with no production configs).

  6. drnick1

    And this is why I handroll my own routers/firewalls, using commodity hardware and a Linux distribution.

  7. ggm

    Have used their travel wifi product back when hotel wifi was a strange beast. Wouldn't expect to need it now eSIM and ubiquitous internet travel pricing means the hotel wifi may be the LEAST valid path to access things.

    I have a free give-away mikrotik unit in the same price bracket (literally free: they were both conference give-aways) it's physically smaller and it runs what appears to be their mainline code. Say what you like about microtik for quality, they provide pretty much every knob and frob you could want.

  8. HDBaseT

    The US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!

More from this day

2026-07-08