8 ms·
Tenda firmware (multiple versions) contains hidden authentication backdoor
- zb3 2mo agoTypical for Chinese companies. Of course US companies also provide backdoors, but more official and more secure..
- seethishat 2mo agoNo backdoor is secure. Read the "Keys under Doormats" paper from 2015: https://www.schneier.com/wp-content/uploads/2016/09/paper-keys-under-doormats-CSAIL.pdf https://www.schneier.com/wp-content/uploads/2016/09/paper-ke...
- Havoc 2mo agoThe consistency with which networking hardware companies produce such garbage is crazy. And it’s always amateur hour backdoors somehow. If it was something sophisticated they might get a pass on „ok some security agency made them do it probably“
- KingOfCoders 2mo agoOr the amateur hour backdoors are those that are found. Or the amateur hour backdoors are there to be found.
- daneel_w 2mo agoThey didn't produce garbage by accident. They followed a plan and made a decision.
- Ekaros 2mo agoSad truth is that too few customers pay extra for proper security. And even then it is questionable will you get it.
- 0xshaftoe 2mo ago[dead]
- dmpanch 2mo ago[flagged]
- pbasista 2mo ago> The associated username is not validated, so any provided username will succeed when paired with the backdoor password. Great. I am really wondering why should the customers trust these manufacturers. At this point I would not use any router with vendor-provided black box firmware. Full stop. I would always install OpenWRT or something similar on it before using it. And if that is not possible for whatever reason, I would not even think about buying such a device.
- deleted 2mo ago[deleted]
- rootatixww3 2mo agogood approach, but your security should not depend on your router anyway, you should be immune to attacks from it
- bayindirh 2mo agoNot exposing your management interface to internet and running a guest network which doesn't have access to said management interfaces can block 95%+ of the attacks, I believe.
- rootatixww3 2mo agoyes, defense in depth
- bayindirh 2mo agoLast time when I looked OpenWRT was unable to support MIMO and beamforming capabilities of many of the devices it was running on. This capabilities are crucial to have decent coverage, signal strength and throughput where I live (i.e.: crowded/congested wireless networks in an apartment complex). Did OpenWRT team managed to work around them, or did the manufacturers started to play nicer with open drivers with loadable firmware?
- 486sx33 2mo ago
- linzhangrun 2mo agoCommon situation for small-company software... Backdoor passwords left for convenient debugging are not surprising anymore.
- daneel_w 2mo agoThis is not a case of "convenient debugging".
- deeddy 2mo agoI've seen it last night, and I was like wtf?! Frankly, if they tried to build in some backdoor, I bet they would have done it differently, not so obviously. This must have been some sort of stupidity done for testing purposes, and just got buried deep in the code and forgotten. This is the main reason why you should always use OpenWRT or other opensource router OS. If it gets an issue, at least it would get patched in the next update.
- high_byte 2mo agothis is definitely a backdoor, not necessarily that they use it to infiltrate users but definitely they put them at risk. reminds me of a bug I found in some tplink router it compared passwords of 3 different users but that table was empty so basically 15 NULL bytes would log you in as admin lol
- Fabricio20 2mo agoOh this is amazing! I have a few of their cube routers sitting around and I always hated how app-locked their firmware was when it really is just a wifi repeater with a few extras (mesh) on top. Root access will do wonders to bypassing the app now (and also disabling their ping-for-green-light mechanism which spams the network with a constant dns resolution to microsoft.com lol). Also honest take this looks less like a "backdoor" (implies malicious - this is a link to a CVE after all) and more like a developer access credential/default credential that was burned into the firmware (i'd imagine the code remains but on a production run they randomize the key so its non-guessable but then you get lazy and dont run that extra step and this slips in/you burn the bare firmware with no production configs).
- tinyhitman 2mo agowhy would a consumer device need a randomized password?
- vajrabum 2mo agoMaybe so when you factory reset the device that it sets the admin to something you can maybe read off the label? At least that way the random attacker needs physical access to your space.
- idiotsecant 2mo agoYes, it is randomized but due to a quirk in the universal probability waveform it always randomizes to 'rzadmin'. Scientists are baffled.
- mjmas 2mo agoPulled out of fair hat. Guaranteed to be random.
- daneel_w 2mo agoWhat a surprise.
- cedel2k1 2mo agoReminds me of LKWPETER. I lost a bet when insinsting this couldn't be true.
- megous 2mo agoMost of the software is this way, it seems. Military intelligenece in our country were recently changing configs on peoples routers without their knowledge or consent to get rid of similarly dangerous thing on several types of tp-link routers. And if you ever looked inside the firmwares of these IoT Linux boxes (be it sip phones, payment terminals, ip cameras, routers, modems, etc.) you'd not want it anywhere near anything that needs to be secure. OpenWRT or your own thing, or very strict isolation, or nothing.
- allankoech 2mo agoWas that admin password intended for internal testing but ended in prod? "Unfortunately, we were unable to reach the vendor" With the widespread adoption of Tenda products in my local area, someone can have a good time exploiting this vulnerability.
- eth0up 2mo ago[dead]
- RetroTechie 2mo ago[flagged]
- cwmoore 2mo agoAre you referring to the concept of “prayer?”
- SubiculumCode 2mo agoUp and out the back door, any 'ol time.
- fusslo 2mo ago> Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. I was unfamiliar with Tenda. > Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile https://www.tendacn.com/us/profile ) Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have no idea if Tenda does this, I've just seen it previously. Specifically with security cameras) I wish the authors provided some method for checking this vulnerability other than fw version. It seems like Tenda could just change the password and say "yep! all safe now"
- jamesnorden 2mo agoThere's claims of it being "the first home-grown router and wireless network device manufacturer in China".
- morpheuskafka 2mo agoMy ex used to work in their sales department lol. But I'd seen them anyway, in the context of cheap unmanaged switches on Amazon. They are not a state owned company or anything so I doubt this is anything too nefarious, likely just absolutely not giving a crap about quality.
- TedDoesntTalk 2mo agoI’m in the USA and have a Tenda WiFi usb stick. Not as popular as other brands but they are around
- dpacmittal 2mo agoTenda is very popular in Asia, several ISPs use them as their default routers.
- userbinator 2mo agoIt is probably just a brand, like many others, and based on a reference design from the OEM. I have a small Tenda 5-port gigabit dumb switch. It uses the same switch chip as this TP-Link, just with different branding; even the "SG105" model number is the same: https://goughlui.com/2022/02/27/unbox-teardown-tp-link-tl-sg105-5-port-gigabit-desktop-ethernet-switch/ https://goughlui.com/2022/02/27/unbox-teardown-tp-link-tl-sg...
- vachina 2mo ago[flagged]
- Terr_ 2mo agoIf you're accusing CERT of hypocrisy, what's an example of the second case?
- murderfs 2mo agoI'll do better than a second case, here's three: Barracuda Networks: https://krebsonsecurity.com/2013/01/backdoors-found-in-barracuda-networks-gear/ https://krebsonsecurity.com/2013/01/backdoors-found-in-barra... Fortinet: https://community.spiceworks.com/t/hard-coded-password-backdoor-found-in-fortinet-firewalls/464379 https://community.spiceworks.com/t/hard-coded-password-backd... Korenix: https://sec-consult.com/vulnerability-lab/advisory/backdoor-account-in-korenix-technology-jetport-series/ https://sec-consult.com/vulnerability-lab/advisory/backdoor-... The fact that the password is "rzadmin" makes it a lot more likely that this is just run of the mill stupidity, and not something more nefarious: you'd want a backdoor that isn't blindingly obvious and usable by the CIA.
- matheusmoreira 2mo agoI was deeply alarmed when I figured out ISPs had effortless remote access to the routers and consequently to my LAN. Now they just provide me an ONT which terminates their fiber and connects into my own hardened GL.iNet router running OpenWRT.
- tangsoupgallery 2mo ago[flagged]
- naturalmovement 2mo ago[flagged]
- nttylock 2mo ago[flagged]
- greyface- 2mo agoThe article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.
- BloondAndDoom 2mo agoAt that point it’s not even a back door it’s just stupid default root password kind of design which used to be standard in this kind of hardware. Backdoor would at least try to be subtle :)
- Asraelite 2mo agoBackdoors are often (almost always?) designed to look like incompetence so that there's plausible deniability.
- ktm5j 2mo agoThat sounds like a fun thing to wonder about, but how could anyone possibly know that for sure?
- eth0up 2mo ago[flagged]
- gunapologist99 2mo agoThat's what makes it plausible deniability.
- eth0up 2mo agoIt's refreshing to see someone around here addressing the compulsively overlooked elephant in the room; plausible deniability. I am not implying it applies directly here, but notice the trend -- it's taboo to even speculate on and often gets rebuke for even hinting at it. The social convention around it is perfect cover. And I am not the only one that knows this. If we were to wake suddenly and realize the scale of relevance here, we'd probably all go full luddite. Call me paranoid though.
- drnick1 2mo agoAnd this is why I handroll my own routers/firewalls, using commodity hardware and a Linux distribution.
- SuperMouse 2mo agoTenda has good support among OpenWRT.
- consp 2mo agoSo the next step is a hardware or boot firmware backdoor? (Good to know it remains useful by using openWRT and doesn't become landfill)
- matltc 2mo agoLooking to do this to get off stock isp leased router. What's your hardware/distro rec?
- yabones 2mo agoYou can use basically any hardware. I've done it with trash-picked laptops and USB ethernet adapters. Best option these days is a N100/N150 mini-pc with multiple NICs onboard, but with the price of everything going up maybe trashpicking will make a return. https://nbailey.ca/post/router https://nbailey.ca/post/router
- dhruvrrp 2mo agoUse openWrt (https://openwrt.org https://openwrt.org), and use their hardware list to pick a consumer router with the feature set you need that can be flashed to use openWrt.
- drnick1 2mo agoRyzen 5 with a dual 10Gbps NIC, running Debian. Overkill for a router/firewall, but I run other services on the same hardware including an email stack, Podman containers, and small AI model for use within Home Assistant. I wouldn't buy new hardware. Any modest machine built in the last decade would do. If possible, get a machine with an internal ATX power supply rather than an external brick, they tend to be more reliable. If all you need is 1Gpbs and WiFi, OpenWrt on consumer hardware is probably enough though.
- ggm 2mo agoHave used their travel wifi product back when hotel wifi was a strange beast. Wouldn't expect to need it now eSIM and ubiquitous internet travel pricing means the hotel wifi may be the LEAST valid path to access things. I have a free give-away mikrotik unit in the same price bracket (literally free: they were both conference give-aways) it's physically smaller and it runs what appears to be their mainline code. Say what you like about microtik for quality, they provide pretty much every knob and frob you could want.
- VladVladikoff 2mo agoI’m working on a hotel right now. And I’ve gone to great lengths to make the wifi more secure. Everyone on their own VLAN. Separate PPSK for each room. Credentials are randomly generated and not some ridiculous pattern of last name and room number or similar. We built our own custom access control system, with what at the time was the strongest keycards we could find (mifare desfire ev3), I’m really trying to make a hotel who’s security isn’t such a joke.
- jeffbee 2mo agoWhat fun is that? It used to be fun to `net send` little notes to strangers in hotels.
- ggm 2mo agoAs long as I can bind more than one device in my room, and as long as I can "see" the devices amongst themselves, I'd love this. I can imagine people who want inter-room access but they can live through proxies offsite. If I want to do in room sharing, I need in room wifi. Gets hard when you bring "smart" TV's to the table. They're going to need to expose into this system somewhat 'credential-free' but if you do it off MAC address then a determined user could disconnect, find MAC, clone ...
- netsharc 2mo agoI stayed at a clinic once, and all the smart TVs were on the same network.. I wonder what would've happened if I streamed a video from my phone to another room's TV.
- HDBaseT 2mo agoThe US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!
- ranger_danger 2mo agoNot sure if you're joking, but both have already done so. And any US company is subject to secret orders forcing them to implement a backdoor if demanded.
- Gigachad 2mo agoThere was a meme going round of a network diagram that layers a Chinese firewall behind a US firewall behind a Russian firewall so they can all block each other countries backdoors.
- sph 2mo agohttps://en.wikipedia.org/wiki/Swiss_cheese_model https://en.wikipedia.org/wiki/Swiss_cheese_model
- k_g_b_ 2mo agoThey'll have a lot of work to do, if they want to catch up with the amount and rate of "hidden authentication backdoors" all those companies (and also Cisco) have. E.g. https://www.thestack.technology/cisco-hard-coding-passwords-products/ https://www.thestack.technology/cisco-hard-coding-passwords-...
- matltc 2mo agoMy ifconfig is simple: if it's made in Shenzhen, throw it out
- dhx 2mo agoIt looks like recent Tenda hardware/firmware is encrypted per below examples, making it harder to audit. binwalk US_AC10V6.0si_V16.03.62.09_multi_TDE01.bin DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 516 0x204 OpenSSL encryption, salted, salt: 0x436999A39FECA649 binwalk US_BE12ProV1.0mt_V16.03.66.23_TD01.bin DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 516 0x204 OpenSSL encryption, salted, salt: 0x81235B7D4130B6AB The third attempt I tried was unencrypted, and possibly reveals the problem exists on another model this CVE doesn't list as affected: binwalk US_W18EV2_kf_V16.01.0.20\(4766\)_HighPower\ \(1\).bin DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 64 0x40 uImage header, header size: 64 bytes, header CRC: 0x95335734, created: 2026-06-16 09:09:35, image size: 2159135 bytes, Data Address: 0x80100000, Entry Point: 0x805F41C0, data CRC: 0x5ABEDB00, OS: Linux, CPU: MIPS, image type: OS Kernel Image, compression type: lzma, image name: "MIPS Tenda Linux-4.14.90" 128 0x80 LZMA compressed data, properties: 0x6D, dictionary size: 8388608 bytes, uncompressed size: 6947248 bytes 2159263 0x20F29F Squashfs filesystem, little endian, version 4.0, compression:xz, size: 8971644 bytes, 847 inodes, blocksize: 1048576 bytes, created: 2026-06-16 08:53:20 Inside is /squashfs-root/webroot_ro/default_ac.cfg which offers: sys.rzadmin.username=rzadmin sys.rzadmin.password=cnphZG1pbg== (ed: base64 decoded: rzadmin) sys.guest.username=guest sys.guest.password=Z3Vlc3Q= (ed: base64 decoded: guest) And /squashfs-root/webroot_ro/default_router.cfg which offers: sys.rzadmin.username=rzadmin sys.rzadmin.password=cnphZG1pbg== (ed: base64 decoded: rzadmin) From what I can see quickly (I haven't looked hard), "sys.rzadmin.password" is only referenced from the login() function of /bin/httpd in the context of retrieving a value. This value is retrieved and compared before the error message "login err: password is wrong." is emitted. I can't find any other reference to code in any part of the firmware that may allow a user to change the default value of "sys.rzadmin.password". Also for fun there is a function imsd_upload_log_v1 in /bin/imsd that collects SSIDs, MACs, IP addresses, sys.admin.username, sys.rzadmin.username, timezone, and another function imsd_remote_pwd_get in /bin/imsd that retrieves sys.admin.password. Related library /lib/lubucapi.so also looks like a fun binary to inspect more closely as it contains a command set that seemingly allows either cloud management of Tenda routers and/or remote debugging, and possibly is why imsd_remote_pwd_get exists in /bin/imsd
- emsign 2mo agoNot to sound too alarming. But Security holes in networking equipment Affects not just the compromised devices.
- like_any_other 2mo agoSo will this finally be treated as sabotage/criminal hacking, or is it just yet another example of letting manufacturers do whatever they want to their customers without any punishment? Meanwhile if I find and publish the emails of Tenda customers that they accidentally left unprotected, I get raided by the FBI.
- finalhacker 2mo agoAlmost all consumer electronics come with backdoors—especially given the prevalence of computational advertising. Before criticizing Tenda, we ought to clarify whether this is a consumer-facing (2C) or business-facing (2B) product.
- chirsz 2mo agoA quick search reveals several other serious vulnerabilities in Tenda routers that could grant administrator privileges. Therefore, I tend to believe this is due to the company's incompetence and lack of technical skill rather than malicious intent—but it's still a reason to avoid using Tenda products. There's a reason why Tenda's market share is far lower than TP-Link's.