Published Jul 23, 2026, 9:30 AM EDT Monica J. White is a journalist with over a decade of experience in covering technology. She built her first PC nearly 20 years ago, and she has since built and tested dozens of PCs. PC hardware is her main beat, and graphics cards and the GPU market at large are her main area of interest, but she has written thousands of articles covering everything related to PCs, laptops, handhelds, and peripherals. From GPUs and CPUs to headsets and software, Monica's always willing to geek out over all things related to computing. Outside of her work with How-To Geek, Monica contributes to TechRadar, PC Gamer, Tom's Guide, Laptop Mag, SlashGear, Whop, and Digital Trends, among others. Her ultimate goal is to make PC gaming and computing approachable and fun to any audience. Monica spends a lot of time elbow-deep in her PC case, as she's always making upgrades, testing something, or plotting out her next build. She's the go-to tech support person in her immediate circle, so she's never out of things to do. Whenever she has spare time, you'll find her gaming until the early hours and hanging out with her dog. Five router firmware builds have just been deemed majorly unsafe, and it isn't the usual patch-it-and-move-on situation. The web interface on these routers has a hidden backdoor password that hands over full admin access, and the username you type doesn't even matter. That sounds grim enough, but it gets worse: The fix isn't coming. What was actually found buried in the firmware The password check has a second, hidden door So, what's going on? The routers I'm talking about are all made by Tenda, and the flaw was documented by Carnegie Mellon's CERT Coordination Center, which tracks and coordinates this sort of disclosure. CERT's note describes an undocumented authentication backdoor sitting in the router's web management interface, which is the page you log into to change your Wi-Fi and network settings. Here's how it works. When you try to log in, the router's web server checks your password the normal way first, but if that check fails, the code doesn't stop there. It reaches for a second password stored in the device's own configuration and compares it against whatever you typed, in plaintext, with no hashing involved. (You can read more about it here.) If that hidden value matches, you're handed full admin control of the router, active session and all. The tech-babble involved in these types of vulnerabilities usually makes them sound less scary than they should be, so to say it plainly, this exploit could potentially hand over control of your entire network. But there's one more gory detail to mention here: the username isn't validated at all, so anyone holding the backdoor password can log in under any name they like, and right now there's no patched firmware to shut the door. UniFi Dream Router 7 9/10 Brand Unifi Range 1,750 square feet If you own one of the affected routers, it's definitely time to move on. The UniFi Dream 7 is made by one of the most recognizable companies in the space, so it'll keep your connection secure. The five affected models, and why there's no fix CERT couldn't even reach Tenda to fix it Credit: Ismar Hrnjicevic / How-To Geek The five Tenda routers flagged here are the FH1201, W15E, AC10, AC5, and AC6, specifically their U.S. firmware builds. CERT reported the problem to Tenda back in May, published the note in July, and claims to have gotten nothing back; nothing, zilch, no response, no statement, and most importantly, no patch. That's what tips this from a bad bug into a genuinely stressful situation, because normally you'd wait for a few days for an update, patch your router, and be done with it. Not this time, though. Before you close this tab because you don't own a Tenda, don't get too comfortable. Abandoned firmware and radio-silent vendors are one thing, but routers that reach EOL are in a similar state of perpetual vulnerability. If something crops up, they won't be fixed, and your router could be sitting on a flaw just like this one. Why a backdoor is even worse than your average router bug This one doesn't even need you to click anything Credit: Nick Lewis / How-To Geek More often than not, getting your network compromised takes a little participation on your part. You click a dodgy link, install something you shouldn't have, or even just use a terrible password. A backdoor like this skips all of that, though; there's no bait that gets you trapped. The router will simply open the door to anyone who shows up with the right key, whether you've been careful or not. And once someone's inside, they're not just poking around. Per CERT, that admin access lets an attacker reconfigure the device, change your network settings, and switch off security features, which in practice means repointing your DNS so you land on fake versions of real sites, snooping on the traffic flowing through your home, or roping your router into a botnet that spends its days attacking other people. What to actually do right now You have options, even without a patch Credit: Sydney Louw Butler / How-To Geek If you own one of these affected models, the honest advice is to get rid of it and get a new one, unless the manufacturer commits to patching this vulnerability. Until you do, CERT has two stopgaps worth applying. First, turn off remote management, sometimes labeled remote web access or WAN management, so the admin page can't be reached from the wider internet. That doesn't remove the backdoor, but it slams the door on anyone trying to walk through it outside of your actual home. CERT's second suggestion is to change the router's default LAN IP address, which makes your admin page a little harder for automated scanners to stumble onto. It's always better to be safe than sorry This Tenda note is one of dozens that land every month, across just about every brand you can possibly name. Researchers pull apart consumer routers constantly, and good thing, too, because then, manufacturers can patch them. Most get patched, some don't. So even if your router isn't on today's list, it could be on tomorrow's, and the single best thing you can do is stop treating it as a set-it-and-forget-it box. Stay on top of firmware updates, and if your router no longer gets them, it's time to let it go. Eero Pro 7 Wi-Fi Router Amazon's Eero brand is another router maker that you can trust, and this one supports high-speed Wi-Fi 7 connectivity.
Your router might have a hidden backdoor password, and the manufacturer isn't fixing it
Full Article
Original Source
Read the full article at Howtogeek →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.