Security researchers disclosed CVE-2026-11405, an undocumented, hardcoded administrative backdoor embedded within the firmware of several popular Tenda enterprise and home router models (including FH1201, W15E, AC10, AC5, and AC6).
The vulnerability allows remote, unauthenticated attackers on the local network or WAN interface to bypass standard password prompts using hidden administrative credentials. Once authenticated, attackers gain complete control over the physical router, allowing them to rewrite system settings, flush firewall rules, and re-route all inbound and outbound network traffic. The Pipeline to Crypto Theft
Edge network hardware sits directly between Web3 infrastructure and the open internet. Breaching hardware routers provides dangerous capabilities for crypto theft:
1. RPC Endpoint Hijacking & Phishing
By taking control of a router, attackers can perform DNS Spoofing. When an end user or developer attempts to connect to a legitimate Web3 RPC endpoint (like Infura, Alchemy, or a local node), the router quietly redirects the connection to a malicious proxy node managed by the hacker. This malicious node serves manipulated state data or injects fraudulent transaction signing requests into browser wallets like MetaMask.
2. Validator Node Exposure & MitM Attacks
Staking operators and homelab engineers hosting validator nodes behind compromised routers face severe risks. Attackers can eavesdrop on unencrypted peer-to-peer gossip traffic, manipulate block propagation timing (leading to slashing penalties), or launch Man-in-the-Middle attacks to intercept signing calls between hot-wallet key managers and validator clients.