CVE-2026-11405
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
06/07/2026
Última modificación:
08/07/2026
Descripción
*** Pendiente de traducción *** The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8.<br />
<br />
- The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key).<br />
- After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration.<br />
- It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password.<br />
<br />
A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA



