Breaking
Endpoint Hardening

Security flaw found in five router models

By Chloe Prescott 4 min read
Security flaw found in five router models - router security
Security flaw found in five router models

Five Tenda Wi-Fi routers contain a hidden backdoor that allows attackers to gain full administrative control, according to a security advisory from the CERT Coordination Center. The vulnerability affects models that may no longer receive firmware updates, leaving users at risk.

Which routers are affected

The flaw exists in five firmware versions tied to Tenda routers:

    • FH1201 High Power AC1200 Dual Band Wireless Router (US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD)
    • W15E v2.0 AC1200 Wireless Hotspot Router (US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE)
    • AC10 v1.0 AC1200 Smart Dual-Band Gigabit Router (US_AC10V1.0re_V15.03.06.46_multi_TDE01)
    • AC5 v1.0 AC1200 Smart Dual-Band Router (US_AC5V1.0RTL_V15.03.06.48_multi_TDE01)
    • AC6 v1.0 AC1200 Router (US_AC6V2.0RTL_V15.03.06.51_multi_T)

Shenzhen Tenda Technology manufactures these devices. Some models have been discontinued, making it uncertain whether patches will be released.

How the backdoor works

The issue arises from a hardcoded backup password—“rzadmin”—embedded in the firmware. Attackers exploit it by accessing the router’s admin login page and entering the password without a username. The device first checks authentication using MD5-based verification, but if that fails, it compares the input with the stored backup password in plain text.

A successful match grants admin-level access and creates a valid session, giving attackers full control over the router’s settings. The CERT report confirmed this process requires no additional steps.

Security experts have repeatedly warned about the dangers of hardcoded credentials, which often remain in devices long after debugging. In this instance, the password was likely left behind unintentionally, though its presence in production firmware indicates poor oversight.

What attackers can do

Once inside, hackers can intercept unencrypted traffic, redirect users to malicious sites, or recruit the router into a botnet. A compromised router can also serve as a gateway to target other devices on the same network, particularly those without built-in security like smart TVs, baby monitors, and security cameras.

Related: Doctor Doom Debuts in Avengers Trailer

While computers and smartphones may have antivirus software, many IoT devices lack even basic protections. A single vulnerable router can expose an entire household or small business to further attacks.

CERT attempted to contact Tenda about the issue but received no response. The advisory stated that coordination with the vendor was not possible. Without a patch, users must take their own precautions to reduce risks.

How to protect yourself

The backdoor is embedded in the firmware, so users cannot remove it by changing settings. The simplest solution is replacing the router with a newer model that still receives security updates, though cost may prevent some from doing so.

For those unable to upgrade immediately, CERT suggests two temporary workarounds:

  • Disable remote web management. This feature, which allows admin access from outside the local network, is off by default. Users who enabled it should turn it off to block external attacks.
  • Change the default LAN IP address. Many hackers scan for routers using common default IP ranges. Altering the router’s local address can make it harder to find during opportunistic attacks, though determined hackers may still locate it.

Neither workaround removes the backdoor entirely, but both lower the risk of exploitation. The advisory warns that these steps may not be sufficient against targeted attacks.

Hardcoded credentials have caused problems before. In 2016, the Mirai botnet used default passwords to infect thousands of IoT devices, causing widespread internet outages. While this Tenda flaw is less extensive, it follows a similar pattern—one that often remains unaddressed until after damage occurs.

Age verification challenges for connected devices highlight broader security gaps in consumer technology.

Chloe Prescott

Leave a Reply

Your email address will not be published. Required fields are marked *