4 ms·
Tenda firmware (multiple versions) contains hidden authentication backdoor
- matltc 3mo agoMy ifconfig is simple: if it's made in Shenzhen, throw it out
- RetroTechie 3mo ago[flagged]
- cwmoore 3mo agoAre you referring to the concept of “prayer?”
- SubiculumCode 3mo agoUp and out the back door, any 'ol time.
- fusslo 3mo ago> Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. I was unfamiliar with Tenda. > Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile https://www.tendacn.com/us/profile ) Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have no idea if Tenda does this, I've just seen it previously. Specifically with security cameras) I wish the authors provided some method for checking this vulnerability other than fw version. It seems like Tenda could just change the password and say "yep! all safe now"
- TedDoesntTalk 3mo agoI’m in the USA and have a Tenda WiFi usb stick. Not as popular as other brands but they are around
- dpacmittal 3mo agoTenda is very popular in Asia, several ISPs use them as their default routers.
- userbinator 3mo agoIt is probably just a brand, like many others, and based on a reference design from the OEM. I have a small Tenda 5-port gigabit dumb switch. It uses the same switch chip as this TP-Link, just with different branding; even the "SG105" model number is the same: https://goughlui.com/2022/02/27/unbox-teardown-tp-link-tl-sg105-5-port-gigabit-desktop-ethernet-switch/ https://goughlui.com/2022/02/27/unbox-teardown-tp-link-tl-sg...
- _puk 3mo agoTenda has been around for quite a few years now. I don't imagine they'll rebrand. I have an ethernet over power adapter somewhere in a cupboard from perhaps 10 years ago. Back then it was standard for the admin password to be 'admin'. They'd often even print it on the device itself.
- ale42 3mo ago> the admin password to be 'admin'. They'd often even print it on the device itself. Yes but aren't you supposed to change that one? The problem with the rzadmin is that it will continue to work even after you change the regular admin one...
- puzzlingcaptcha 3mo agoI am still using their Powerline adapters and FWIW they have been very reliable.
- jamesnorden 3mo agoThere's claims of it being "the first home-grown router and wireless network device manufacturer in China".
- vachina 3mo ago[flagged]
- Terr_ 3mo agoIf you're accusing CERT of hypocrisy, what's an example of the second case?
- murderfs 3mo agoI'll do better than a second case, here's three: Barracuda Networks: https://krebsonsecurity.com/2013/01/backdoors-found-in-barracuda-networks-gear/ https://krebsonsecurity.com/2013/01/backdoors-found-in-barra... Fortinet: https://community.spiceworks.com/t/hard-coded-password-backdoor-found-in-fortinet-firewalls/464379 https://community.spiceworks.com/t/hard-coded-password-backd... Korenix: https://sec-consult.com/vulnerability-lab/advisory/backdoor-account-in-korenix-technology-jetport-series/ https://sec-consult.com/vulnerability-lab/advisory/backdoor-... The fact that the password is "rzadmin" makes it a lot more likely that this is just run of the mill stupidity, and not something more nefarious: you'd want a backdoor that isn't blindingly obvious and usable by the CIA.
- matheusmoreira 3mo agoI was deeply alarmed when I figured out ISPs had effortless remote access to the routers and consequently to my LAN. Now they just provide me an ONT which terminates their fiber and connects into my own hardened GL.iNet router running OpenWRT.
- tangsoupgallery 3mo ago[flagged]
- naturalmovement 3mo ago[flagged]
- nttylock 3mo ago[flagged]
- greyface- 3mo agoThe article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.
- lemagedurage 3mo agoSounds like a convenience feature for a dev that they forgot to remove before distribution, since it's this poorly hidden.
- sph 3mo agoIn computer security, never attribute to ignorance that which is adequately explained by malice.
- hnlmorg 3mo agoYou’ve got the saying backwards: “Never attribute to malice that which is adequately explained by stupidity.” https://en.wikipedia.org/wiki/Hanlon%27s_razor https://en.wikipedia.org/wiki/Hanlon%27s_razor
- drnick1 3mo agoAnd this is why I handroll my own routers/firewalls, using commodity hardware and a Linux distribution.
- matltc 3mo agoLooking to do this to get off stock isp leased router. What's your hardware/distro rec?
- dhruvrrp 3mo agoUse openWrt (https://openwrt.org https://openwrt.org), and use their hardware list to pick a consumer router with the feature set you need that can be flashed to use openWrt.
- drnick1 3mo agoRyzen 5 with a dual 10Gbps NIC, running Debian. Overkill for a router/firewall, but I run other services on the same hardware including an email stack, Podman containers, and small AI model for use within Home Assistant. I wouldn't buy new hardware. Any modest machine built in the last decade would do. If possible, get a machine with an internal ATX power supply rather than an external brick, they tend to be more reliable. If all you need is 1Gpbs and WiFi, OpenWrt on consumer hardware is probably enough though.
- consp 3mo agoI have a Lenovo thin client running Debian as internet gateway/firewall. With some minor modifications and a small low power blower fan you can add a dual sfp pcie card in it (not all versions can, though there are more manufacturers of thin clients with 4x pcie slots). The blower fan is because the main fan stops often and it needs some cooling.
- yabones 3mo agoYou can use basically any hardware. I've done it with trash-picked laptops and USB ethernet adapters. Best option these days is a N100/N150 mini-pc with multiple NICs onboard, but with the price of everything going up maybe trashpicking will make a return. https://nbailey.ca/post/router https://nbailey.ca/post/router
- ggm 3mo agoHave used their travel wifi product back when hotel wifi was a strange beast. Wouldn't expect to need it now eSIM and ubiquitous internet travel pricing means the hotel wifi may be the LEAST valid path to access things. I have a free give-away mikrotik unit in the same price bracket (literally free: they were both conference give-aways) it's physically smaller and it runs what appears to be their mainline code. Say what you like about microtik for quality, they provide pretty much every knob and frob you could want.
- VladVladikoff 3mo agoI’m working on a hotel right now. And I’ve gone to great lengths to make the wifi more secure. Everyone on their own VLAN. Separate PPSK for each room. Credentials are randomly generated and not some ridiculous pattern of last name and room number or similar. We built our own custom access control system, with what at the time was the strongest keycards we could find (mifare desfire ev3), I’m really trying to make a hotel who’s security isn’t such a joke.
- ggm 3mo agoAs long as I can bind more than one device in my room, and as long as I can "see" the devices amongst themselves, I'd love this. I can imagine people who want inter-room access but they can live through proxies offsite. If I want to do in room sharing, I need in room wifi. Gets hard when you bring "smart" TV's to the table. They're going to need to expose into this system somewhat 'credential-free' but if you do it off MAC address then a determined user could disconnect, find MAC, clone ...
- ikidd 3mo agoIt would still be wiser to tie your own router into the hotel system as a gateway, and keep your own PAN behind that.
- netsharc 3mo agoI stayed at a clinic once, and all the smart TVs were on the same network.. I wonder what would've happened if I streamed a video from my phone to another room's TV.
- HDBaseT 3mo agoThe US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!
- ranger_danger 3mo agoNot sure if you're joking, but both have already done so. And any US company is subject to secret orders forcing them to implement a backdoor if demanded.
- Gigachad 3mo agoThere was a meme going round of a network diagram that layers a Chinese firewall behind a US firewall behind a Russian firewall so they can all block each other countries backdoors.
- sph 3mo agohttps://en.wikipedia.org/wiki/Swiss_cheese_model https://en.wikipedia.org/wiki/Swiss_cheese_model
- k_g_b_ 3mo agoThey'll have a lot of work to do, if they want to catch up with the amount and rate of "hidden authentication backdoors" all those companies (and also Cisco) have. E.g. https://www.thestack.technology/cisco-hard-coding-passwords-products/ https://www.thestack.technology/cisco-hard-coding-passwords-...
- dhx 3mo agoIt looks like recent Tenda hardware/firmware is encrypted per below examples, making it harder to audit. binwalk US_AC10V6.0si_V16.03.62.09_multi_TDE01.bin DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 516 0x204 OpenSSL encryption, salted, salt: 0x436999A39FECA649 binwalk US_BE12ProV1.0mt_V16.03.66.23_TD01.bin DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 516 0x204 OpenSSL encryption, salted, salt: 0x81235B7D4130B6AB The third attempt I tried was unencrypted, and possibly reveals the problem exists on another model this CVE doesn't list as affected: binwalk US_W18EV2_kf_V16.01.0.20\(4766\)_HighPower\ \(1\).bin DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 64 0x40 uImage header, header size: 64 bytes, header CRC: 0x95335734, created: 2026-06-16 09:09:35, image size: 2159135 bytes, Data Address: 0x80100000, Entry Point: 0x805F41C0, data CRC: 0x5ABEDB00, OS: Linux, CPU: MIPS, image type: OS Kernel Image, compression type: lzma, image name: "MIPS Tenda Linux-4.14.90" 128 0x80 LZMA compressed data, properties: 0x6D, dictionary size: 8388608 bytes, uncompressed size: 6947248 bytes 2159263 0x20F29F Squashfs filesystem, little endian, version 4.0, compression:xz, size: 8971644 bytes, 847 inodes, blocksize: 1048576 bytes, created: 2026-06-16 08:53:20 Inside is /squashfs-root/webroot_ro/default_ac.cfg which offers: sys.rzadmin.username=rzadmin sys.rzadmin.password=cnphZG1pbg== (ed: base64 decoded: rzadmin) sys.guest.username=guest sys.guest.password=Z3Vlc3Q= (ed: base64 decoded: guest) And /squashfs-root/webroot_ro/default_router.cfg which offers: sys.rzadmin.username=rzadmin sys.rzadmin.password=cnphZG1pbg== (ed: base64 decoded: rzadmin) From what I can see quickly (I haven't looked hard), "sys.rzadmin.password" is only referenced from the login() function of /bin/httpd in the context of retrieving a value. This value is retrieved and compared before the error message "login err: password is wrong." is emitted. I can't find any other reference to code in any part of the firmware that may allow a user to change the default value of "sys.rzadmin.password". Also for fun there is a function imsd_upload_log_v1 in /bin/imsd that collects SSIDs, MACs, IP addresses, sys.admin.username, sys.rzadmin.username, timezone, and another function imsd_remote_pwd_get in /bin/imsd that retrieves sys.admin.password. Related library /lib/lubucapi.so also looks like a fun binary to inspect more closely as it contains a command set that seemingly allows either cloud management of Tenda routers and/or remote debugging, and possibly is why imsd_remote_pwd_get exists in /bin/imsd
- emsign 3mo agoNot to sound too alarming. But Security holes in networking equipment Affects not just the compromised devices.
- like_any_other 3mo agoSo will this finally be treated as sabotage/criminal hacking, or is it just yet another example of letting manufacturers do whatever they want to their customers without any punishment? Meanwhile if I find and publish the emails of Tenda customers that they accidentally left unprotected, I get raided by the FBI.
- finalhacker 3mo agoAlmost all consumer electronics come with backdoors—especially given the prevalence of computational advertising. Before criticizing Tenda, we ought to clarify whether this is a consumer-facing (2C) or business-facing (2B) product.
- chirsz 3mo agoA quick search reveals several other serious vulnerabilities in Tenda routers that could grant administrator privileges. Therefore, I tend to believe this is due to the company's incompetence and lack of technical skill rather than malicious intent—but it's still a reason to avoid using Tenda products. There's a reason why Tenda's market share is far lower than TP-Link's.
- Havoc 3mo agoThe consistency with which networking hardware companies produce such garbage is crazy. And it’s always amateur hour backdoors somehow. If it was something sophisticated they might get a pass on „ok some security agency made them do it probably“
- KingOfCoders 3mo agoOr the amateur hour backdoors are those that are found. Or the amateur hour backdoors are there to be found.
- daneel_w 3mo agoThey didn't produce garbage by accident. They followed a plan and made a decision.
- Ekaros 3mo agoSad truth is that too few customers pay extra for proper security. And even then it is questionable will you get it.
- 0xshaftoe 3mo ago[dead]
- dmpanch 3mo ago[flagged]
- pbasista 3mo ago> The associated username is not validated, so any provided username will succeed when paired with the backdoor password. Great. I am really wondering why should the customers trust these manufacturers. At this point I would not use any router with vendor-provided black box firmware. Full stop. I would always install OpenWRT or something similar on it before using it. And if that is not possible for whatever reason, I would not even think about buying such a device.
- deleted 3mo ago[deleted]
- rootatixww3 3mo agogood approach, but your security should not depend on your router anyway, you should be immune to attacks from it
- bayindirh 3mo agoNot exposing your management interface to internet and running a guest network which doesn't have access to said management interfaces can block 95%+ of the attacks, I believe.
- rootatixww3 3mo agoyes, defense in depth
- bayindirh 3mo agoLast time when I looked OpenWRT was unable to support MIMO and beamforming capabilities of many of the devices it was running on. This capabilities are crucial to have decent coverage, signal strength and throughput where I live (i.e.: crowded/congested wireless networks in an apartment complex). Did OpenWRT team managed to work around them, or did the manufacturers started to play nicer with open drivers with loadable firmware?
- 486sx33 3mo ago
- linzhangrun 3mo agoCommon situation for small-company software... Backdoor passwords left for convenient debugging are not surprising anymore.
- daneel_w 3mo agoThis is not a case of "convenient debugging".
- deeddy 3mo agoI've seen it last night, and I was like wtf?! Frankly, if they tried to build in some backdoor, I bet they would have done it differently, not so obviously. This must have been some sort of stupidity done for testing purposes, and just got buried deep in the code and forgotten. This is the main reason why you should always use OpenWRT or other opensource router OS. If it gets an issue, at least it would get patched in the next update.
- high_byte 3mo agothis is definitely a backdoor, not necessarily that they use it to infiltrate users but definitely they put them at risk. reminds me of a bug I found in some tplink router it compared passwords of 3 different users but that table was empty so basically 15 NULL bytes would log you in as admin lol
- Fabricio20 3mo agoOh this is amazing! I have a few of their cube routers sitting around and I always hated how app-locked their firmware was when it really is just a wifi repeater with a few extras (mesh) on top. Root access will do wonders to bypassing the app now (and also disabling their ping-for-green-light mechanism which spams the network with a constant dns resolution to microsoft.com lol). Also honest take this looks less like a "backdoor" (implies malicious - this is a link to a CVE after all) and more like a developer access credential/default credential that was burned into the firmware (i'd imagine the code remains but on a production run they randomize the key so its non-guessable but then you get lazy and dont run that extra step and this slips in/you burn the bare firmware with no production configs).
- tinyhitman 3mo agowhy would a consumer device need a randomized password?
- vajrabum 3mo agoMaybe so when you factory reset the device that it sets the admin to something you can maybe read off the label? At least that way the random attacker needs physical access to your space.
- idiotsecant 3mo agoYes, it is randomized but due to a quirk in the universal probability waveform it always randomizes to 'rzadmin'. Scientists are baffled.
- mjmas 3mo agoPulled out of fair hat. Guaranteed to be random.
- zb3 3mo agoTypical for Chinese companies. Of course US companies also provide backdoors, but more official and more secure..
- seethishat 3mo agoNo backdoor is secure. Read the "Keys under Doormats" paper from 2015: https://www.schneier.com/wp-content/uploads/2016/09/paper-keys-under-doormats-CSAIL.pdf https://www.schneier.com/wp-content/uploads/2016/09/paper-ke...
- daneel_w 3mo agoWhat a surprise.
- cedel2k1 3mo agoReminds me of LKWPETER. I lost a bet when insinsting this couldn't be true.
- megous 3mo agoMost of the software is this way, it seems. Military intelligenece in our country were recently changing configs on peoples routers without their knowledge or consent to get rid of similarly dangerous thing on several types of tp-link routers. And if you ever looked inside the firmwares of these IoT Linux boxes (be it sip phones, payment terminals, ip cameras, routers, modems, etc.) you'd not want it anywhere near anything that needs to be secure. OpenWRT or your own thing, or very strict isolation, or nothing.
- allankoech 3mo agoWas that admin password intended for internal testing but ended in prod? "Unfortunately, we were unable to reach the vendor" With the widespread adoption of Tenda products in my local area, someone can have a good time exploiting this vulnerability.
- eth0up 3mo ago[dead]