Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available
2026-07-07T14:51:46Z•19be13e94bf6e4e07499e854c457ec72d2459fc8d143057679380a7159c6bb6a
AI-generated malwareAdobe ColdFusionArmored Likho APTBad EpollBusySnake StealerCERT/CCCVE-2026-11405CVE-2026-46242CVE-2026-48282FatFsIoTJanuscapeKasperskyLinux KVMMedtronic data breachShinyHuntersTendaVM escapehidden web promptsprompt injectionrouter backdoorrunZero
What happened
A set of high-impact security events and vulnerabilities was reported: CERT/CC disclosed an undocumented backdoor in multiple Tenda routers (CVE-2026-11405) that grants admin access with a hidden password and has no patch available; Adobe ColdFusion suffers a critical path-traversal RCE (CVE-2026-48282) actively exploited in the wild; a 16-year-old Linux KVM use-after-free (Januscape) enables host memory corruption and potential VM escape; and the Bad Epoll kernel flaw (CVE-2026-46242) allows local privilege escalation to root on Linux and Android. Additional findings include seven FatFs flaws
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 19be13e94bf6e4e07499e854c457ec72d2459fc8d143057679380a7159c6bb6a
- Enrichment time
- 2026-07-07T14:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.