Security flaw discovered in Tenda WiFi routers sold in Slovakia
The CERT Coordination Center at Carnegie Mellon University has reported a firmware vulnerability (CVE‑2026‑11405) in several Tenda Wi‑Fi router models. The flaw could allow an attacker to bypass the standard password and gain full administrative access by using an alternate password stored in the device configuration. Affected firmware versions are listed for the AC5, AC6, AC10, FH1201 and W15E models, though experts dispute whether the issue also applies to the G300 version.
Tenda has not responded to inquiries and has not issued a patch. Security specialists advise users to disable remote management, change default LAN IP addresses, and apply any firmware updates as soon as they become available. The routers are widely sold in Slovakia, but it remains unclear which specific units on the Slovak market are impacted.
The discovery highlights broader concerns about backdoor‑like mechanisms in consumer networking equipment and underscores the need for users to monitor security advisories for their devices.