VU#213560: Tenda firmware (multiple versions) contains hidden authentication backdoor

2026-07-06T20:52:12Z9a5ee427ddc6c1a9c42c246b2944292bcce09b80959b97e71753a7d82744aa4c
FastStoneHPLittleOrbitSignalRGBTendaanti-cheatauthentication-bypassbackdoorcredential-disclosurefirmwareheap-overflowimage-parsinginteger-overflowioctlkernel-driverlocal-privilege-escalationmissing-authorizationnull-dereferenceprinterremote-code-executionroutersecure-boot-bypassuefiwinre-bypass

What happened

Multiple high-impact vulnerabilities across consumer and enterprise products: Tenda router firmware contains an undocumented authentication backdoor allowing admin access without valid credentials (CVE-2026-11405); HP Deskjet 2800 Series firmware exposes backend APIs and Wi‑Fi/admin configuration via missing authorization (CVE-2026-13753); Little Orbit’s GFAC kernel driver (GFAC.sys) has multiple local privilege escalation and DoS flaws (CVE-2026-12166, CVE-2026-12167, CVE-2026-12168); FastStone Image Viewer 8.3 has a JP2 heap overflow and PSD integer overflow that can lead to remote code exec

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
9a5ee427ddc6c1a9c42c246b2944292bcce09b80959b97e71753a7d82744aa4c
Enrichment time
2026-07-06T20:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#213560: Tenda firmware (multiple versions) contains hidden authentication backdoor · Baitaphish