Your router might have a hidden backdoor password, and the manufacturer isn’t fixing it

Five router firmware builds have just been deemed majorly unsafe, and it isn’t the usual patch-it-and-move-on situation. The web interface on these routers has a hidden backdoor password that hands over full admin access, and the username you type doesn’t even matter.

That sounds grim enough, but it gets worse: The fix isn’t coming.

What was actually found buried in the firmware

The password check has a second, hidden door

So, what’s going on? The routers I’m talking about are all made by Tenda, and the flaw was documented by Carnegie Mellon’s CERT Coordination Center, which tracks and coordinates this sort of disclosure. CERT’s note describes an undocumented authentication backdoor sitting in the router’s web management interface, which is the page you log into to change your Wi-Fi and network settings.

Here’s how it works. When you try to log in, the router’s web server checks your password the normal way first, but if that check fails, the code doesn’t stop there. It reaches for a second password stored in the device’s own configuration and compares it against whatever you typed, in plaintext, with no hashing involved. (You can read more about it here.)

If that hidden value matches, you’re handed full admin control of the router, active session and all. The tech-babble involved in these types of vulnerabilities usually makes them sound less scary than they should be, so to say it plainly, this exploit could potentially hand over control of your entire network.

But there’s one more gory detail to mention here: the username isn’t validated at all, so anyone holding the backdoor password can log in under any name they like, and right now there’s no patched firmware to shut the door.

The Unifi Dream Router 7.

9/10

Brand

Unifi

Range

1,750 square feet

If you own one of the affected routers, it’s definitely time to move on. The UniFi Dream 7 is made by one of the most recognizable companies in the space, so it’ll keep your connection secure.


The five affected models, and why there’s no fix

CERT couldn’t even reach Tenda to fix it

A Mercusys BE3600 MR25BE Wi-Fi 7 router. Credit: Ismar Hrnjicevic / How-To Geek

The five Tenda routers flagged here are the FH1201, W15E, AC10, AC5, and AC6, specifically their U.S. firmware builds. CERT reported the problem to Tenda back in May, published the note in July, and claims to have gotten nothing back; nothing, zilch, no response, no statement, and most importantly, no patch.

That’s what tips this from a bad bug into a genuinely stressful situation, because normally you’d wait for a few days for an update, patch your router, and be done with it. Not this time, though.

Before you close this tab because you don’t own a Tenda, don’t get too comfortable. Abandoned firmware and radio-silent vendors are one thing, but routers that reach EOL are in a similar state of perpetual vulnerability. If something crops up, they won’t be fixed, and your router could be sitting on a flaw just like this one.

Why a backdoor is even worse than your average router bug

This one doesn’t even need you to click anything

A Raspberry Pi 4 configured to work as a travel router. Credit: Nick Lewis / How-To Geek

More often than not, getting your network compromised takes a little participation on your part. You click a dodgy link, install something you shouldn’t have, or even just use a terrible password. A backdoor like this skips all of that, though; there’s no bait that gets you trapped. The router will simply open the door to anyone who shows up with the right key, whether you’ve been careful or not.

And once someone’s inside, they’re not just poking around. Per CERT, that admin access lets an attacker reconfigure the device, change your network settings, and switch off security features, which in practice means repointing your DNS so you land on fake versions of real sites, snooping on the traffic flowing through your home, or roping your router into a botnet that spends its days attacking other people.

What to actually do right now

You have options, even without a patch

Tp-Link Deco M5 mesh router with one open Ethernet port. Credit: Sydney Louw Butler / How-To Geek

If you own one of these affected models, the honest advice is to get rid of it and get a new one, unless the manufacturer commits to patching this vulnerability.

Until you do, CERT has two stopgaps worth applying. First, turn off remote management, sometimes labeled remote web access or WAN management, so the admin page can’t be reached from the wider internet. That doesn’t remove the backdoor, but it slams the door on anyone trying to walk through it outside of your actual home.

CERT’s second suggestion is to change the router’s default LAN IP address, which makes your admin page a little harder for automated scanners to stumble onto.


It’s always better to be safe than sorry

This Tenda note is one of dozens that land every month, across just about every brand you can possibly name.

Researchers pull apart consumer routers constantly, and good thing, too, because then, manufacturers can patch them. Most get patched, some don’t.

So even if your router isn’t on today’s list, it could be on tomorrow’s, and the single best thing you can do is stop treating it as a set-it-and-forget-it box. Stay on top of firmware updates, and if your router no longer gets them, it’s time to let it go.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *