CVE-2026-11405
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/07/2026
Last modified:
08/07/2026
Description
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.<br />
<br />
- The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).<br />
- After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.<br />
- It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.<br />
<br />
A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



