A hidden admin access exploit sitting in your living room
The Tenda router backdoor is an undocumented admin password baked into specific firmware versions that lets anyone bypass normal login checks, gain full administrator access to the router’s web interface without knowing the real password, and remotely take control of your home network over the internet.
This is not a minor configuration mistake; it is a built-in admin access exploit sitting in the core of the firmware. An unnamed researcher found that several Tenda models will accept a secret alternative password and skip the usual username-plus-password login flow, then grant full admin rights and create a valid session. In other words, if someone on the internet knows this hard-coded value, your password no longer matters. Given how widely details of the backdoor are now circulating and how popular these routers are, it is reasonable to assume attackers will try to automate scans and exploit attempts. That makes this a serious router security threat for ordinary households, not a theoretical lab finding.
Which Tenda routers and firmware are affected?
The undocumented backdoor has been confirmed in five firmware versions that correspond to five older Tenda routers, some of which are already discontinued. The affected builds are: • US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD – FH1201 High Power AC1200 Dual Band Wireless Router • US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE – W15E v2.0 AC1200 Wireless Hotspot Router • US_AC10V1.0re_V15.03.06.46_multi_TDE01 – AC10 v1.0 AC1200 Smart Dual‑Band Gigabit Router • US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 – AC5 v1.0 AC1200 Smart Dual‑Band Router • US_AC6V2.0RTL_V15.03.06.51_multi_T – AC6 v1.0 AC1200 Router
If you own one of these models, you should assume you are exposed unless you have replaced the firmware with a known-good build—which in practice you probably have not, because custom open-source firmware does not support these custom chipsets. Even if your exact model name differs slightly on the label, log in to your router’s admin page and check the firmware version string against the list above. If it matches, you need to treat your router as compromised-by-design until you apply the available workaround or replace the hardware.
Why this backdoor is a direct threat to your home and smart devices
Allowing anyone to skip authentication and gain role=2 admin-level access turns your router into a convenient foothold for attackers. Once inside the web interface, an intruder can scan your internal network, see every connected phone, laptop, and smart home device, and start probing them for more weaknesses. They can read your Wi‑Fi passcodes, silently change DNS settings, redirect specific ports and web traffic to servers they control, and disable security features designed to block suspicious connections.
Because this admin access exploit can be triggered remotely over the internet, attackers do not need physical access to your home or even knowledge of your usual router password. All they need is to find your router online and send the hidden password. That makes the Tenda router backdoor more than a vendor embarrassment; it is a live router security threat to home offices, family networks, and every smart light, camera, or speaker behind them.
The uncomfortable truth: there is no firmware patch yet
Right now, there is no firmware vulnerability fix from Tenda. The coordination center that published the advisory says it was unable to reach the vendor to coordinate a patch, and the company has not provided a public timeline for any update. That means affected routers are shipping—and still running in homes—with a known backdoor and no official remediation.
There is also no realistic alternative firmware escape hatch. Attempts to use popular open-source router firmware have hit a dead end because these devices rely on custom chipsets that those projects do not support. Users are stuck between living with a known admin access exploit, applying a partial workaround, or retiring the affected hardware entirely. From a security standpoint, continuing to run these firmware versions without changes is the worst of all choices: it hands attackers easy, passwordless entry to the heart of your network.
Your one effective defense while you wait (or move on)
Until a firmware vulnerability fix arrives—if it ever does—your best and only meaningful defense is to make the router much harder to reach from the internet. Both the advisory and independent testing point to the same mitigation: disable remote web management and change the default LAN IP address.
- Log in to the router’s web interface from inside your network.
- Find the Remote Management or Remote Web Management setting and turn it off.
- Locate the LAN or Local Network settings and change the default LAN IP (for example, away from the factory 192.168.x.x value).
- Save, reboot, then confirm you can no longer access the admin page from outside your network.
Disabling remote web management removes the easiest path for attackers scanning the internet for exposed admin pages, while changing the default LAN IP helps evade automated tools that target factory settings. For less technical users—or anyone unwilling to trust a router with a known backdoor—the most honest advice is to replace the device with a model whose firmware is not known to contain hidden access paths. In security, obscuring the problem is never enough; either you close the door or you stop using the lock altogether.





