CVE-2026-11405

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/07/2026
Last modified:
08/07/2026

Description

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.<br /> <br /> - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).<br /> - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.<br /> - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.<br /> <br /> A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor