MilikMilik

Five Popular Tenda Routers Expose Your Network to Silent Takeover

Five Popular Tenda Routers Expose Your Network to Silent Takeover
Interest|Home Networking Setup

A Hidden Router Backdoor That Hands Attackers the Keys

The main topic is a newly discovered router firmware backdoor in several Tenda Wi-Fi routers that silently grants full administrative access to the device’s web interface, allowing attackers to seize control of your network without authentication and highlighting a broader pattern of insecure design in consumer IoT products. This is not a theoretical Wi-Fi router vulnerability; it is a design decision that turns your router into a welcome mat for intruders. The CERT Coordination Center reports that five Tenda Wi-Fi routers contain a hidden backdoor in their firmware that grants full administrative control to the router’s web interface. In other words, someone who knows the trick does not need your password. They can reconfigure your network, reroute traffic, or lock you out entirely. Leaving a backdoor like this in production hardware is not a minor oversight. It is an open invitation to a network security breach that users cannot reasonably defend against without replacing or isolating the hardware.

Which Tenda Routers Are Affected—and Why That Matters

This specific Tenda router security flaw affects five models that many households and small offices may still be running. The firmware versions carrying the undocumented router firmware backdoor are US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD, US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE, US_AC10V1.0re_V15.03.06.46_multi_TDE01, US_AC5V1.0RTL_V15.03.06.48_multi_TDE01, and US_AC6V2.0RTL_V15.03.06.51_multi_T. The corresponding devices are the FH1201 High Power AC1200 Dual Band Wireless Router, W15E v2.0 AC1200 Wireless Hotspot Router, AC10 v1.0 AC1200 Smart Dual-Band Gigabit router, AC5 v1.0 AC1200 Smart Dual-Band router, and AC6 v1.0 AC1200 router. Some of these routers appear to have been discontinued, meaning they might not even get updates from the manufacturer if it decides to remedy the situation. When a discontinued router ships with an undocumented backdoor, the risk is structural: owners are left with hardware that may never be patched while sitting at the center of their home network.

Shark Vacuums Show the Same Broken Thinking in the Cloud

The Tenda case is not an isolated blunder; the same pattern appears in other IoT devices, such as Shark robot vacuums that use cloud certificates and policies as if no attacker will ever pry them loose. Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext. The flaw stems from a policy that was never scoped to the device holding the certificate; present it to Shark’s cloud broker, and the broker accepts whatever you publish, addressed to any device it serves. That is not an accident of complex code; it is permissive design that ignores the obvious abuse case. AWS’s own Device Defender flags such overly permissive policies as critical, warning that a compromised certificate can "read or modify shadows, jobs, or job executions for all your devices."

Five Popular Tenda Routers Expose Your Network to Silent Takeover

How Wide Could the Damage Spread?

If you think this is niche, the numbers say otherwise. Watching one AWS region for 24 hours, researcher tokay0 counted 1,517,605 unique Shark serial numbers, of which 673,816, or 44%, emitted an Exec_Response, which he treats as confirmation that the device runs the command handler. Those are devices observed replying, not devices tested or compromised, and he says the true number is likely higher. Not every certificate is a skeleton key, but any vacuum whose certificate carries the broken policy becomes a key, and any vacuum that implements Exec_Command becomes a target. He even showed a cross-model attack path: using one RV2320EDUS certificate to land a reverse shell on an AV1102ARUS bought purely as a target and then pulling a live camera feed while driving the robot around. He never examined the rest of SharkNinja’s connected lineup either, the smart grills and wireless meat probes, which he says are probably vulnerable too. This is how firmware and cloud policy flaws scale into region-wide network security breaches.

What You Should Do Right Now—and Why Firmware Can’t Be Ignored

For both routers and vacuums, the uncomfortable truth is that owners have limited options when vendors ship insecure designs and leave them unpatched. You can use a router without updating it, but there is a security risk that comes with it. Without firmware updates, the router remains vulnerable if a flaw exists that hackers can exploit. Some affected Tenda routers may never see a fix because they appear to be discontinued. In the Shark case, the fix is not the owner's to install; it lives in SharkNinja's AWS account, not the robot's firmware, and until the company replaces the non-compliant policy or properly reissues certificates, the only mitigation available to an owner is to disconnect the vacuum from Wi-Fi. That ends app control, scheduling, and maps, and turns the product back into a vacuum. Meanwhile, SharkNinja had published nothing on the flaw months after initial contact and had not delivered its promised completion date. Firmware and cloud policies are now as central to home security as locks on your doors. Treat any Wi-Fi router vulnerability or IoT policy flaw as a direct risk to your household network, and choose vendors whose update behavior proves they understand that.

Milik earns a commission when you shop through our links, at no extra cost to you. Editorial content is independently selected by our team.

Related Products

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!