READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Tenda Routers Contain a Hardcoded Backdoor Password. The Company Has Not Responded.

Tenda Routers Contain a Hardcoded Backdoor Password. The Company Has Not Responded.
An anonymous researcher found an undocumented admin password baked into multiple Tenda router firmware versions, giving anyone who knows it full access to the device's settings remotely. Tenda has not responded to CERT or to press inquiries. Until a patch arrives, owners should disable remote web management immediately.

What Was Found

The CERT Coordination Center (CERT/CC) disclosed a hardcoded backdoor in several firmware versions released for Tenda-brand routers. Tenda manufactures routers, switches, access points, and video cameras, and sells its hardware through mainstream retail channels including Amazon.

The backdoor is a factory-set admin username and password embedded directly in the firmware. Anyone who knows those credentials can bypass the router's normal access controls and reach the device's internal administration panel without physical access.

What an Attacker Can Do With It

Router admin access is not a minor foothold. From the administration panel, an attacker can scan the internal network to inventory every connected device, pull stored Wi-Fi passwords, redirect web traffic or specific ports to destinations of their choosing, and turn off security features.

All of that is achievable remotely over the internet, according to CERT/CC's reporting. This is not a local-network-only problem.

How It Was Confirmed

The vulnerability was discovered by an anonymous researcher and reported to CERT/CC. Adrian Kingsley-Hughes, writing for ZDNet, reported that he independently located the backdoor credentials and confirmed they worked against Tenda hardware he had on hand. He described the credentials as not difficult to find.

CERT/CC has not published the specific username and password combination publicly, but Kingsley-Hughes's confirmation that the credentials are already findable means the attack surface is effectively open.

Tenda Has Gone Silent

CERT/CC stated it "were unable to reach the vendor to coordinate this vulnerability." ZDNet also reached out to Tenda for comment and a patch timeline and, as of the time of writing, the company had not replied.

The Legitimate Concern Worth Considering

One defensible read on a hardcoded backdoor like this: it may have been added as a technical-support mechanism for situations where a user locks themselves out of their own router, a common consumer problem. Remote support access built into firmware is not unheard of in consumer networking equipment.

Whether the backdoor was added with malicious intent or as a lazy support shortcut, the result is the same: anyone who knows the password can access your router.

What You Can Do Right Now

Because Tenda uses custom chipsets, open-source firmware alternatives like DD-WRT are not available as a workaround. That option is off the table.

The immediate mitigation steps, per the CERT/CC disclosure:

  • Disable remote web management on your Tenda router. This prevents the backdoor from being exploited over the internet.
  • Change the default LAN IP address. This adds a layer of obscurity that complicates automated scanning attacks.

These are stopgaps, not fixes. They reduce exposure but do not close the backdoor.

The Unresolved Question

CERT/CC has been unable to establish contact with Tenda to coordinate a patch timeline. Until Tenda responds publicly, there is no way to know whether a firmware update is days, weeks, or months away, or whether one is planned at all. Owners of affected hardware are running on interim mitigations with no confirmed remediation date.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ZDNETYour Tenda router could have a hidden firmware backdoor - disable this setting ASAP