Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-11405

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
06/07/2026
Última modificación:
08/07/2026

Descripción

*** Pendiente de traducción *** The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.<br /> <br /> - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).<br /> - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.<br /> - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.<br /> <br /> A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor