A budget router can be an open door to the company's network.
On Monday, CERT/CC confirmed the existence of a "hidden password" (backdoor) in certain firmware versions of Tenda routers—the FH1201, W15E, AC10, AC5, and AC6 models. Anyone who knows this password gains full administrative control over the device, regardless of the password you have set. There is currently no update available from the manufacturer.
What are you doing today:
- Check which router the company is using. If it's a Tenda, note the model and firmware version.
- Disable remote/WAN management in the router settings.
- Change the default IP address of the local network—this reduces the chances of being detected by automated scans.
A budget router isn't a problem in and of itself. A router that no longer receives security updates, however, is.
Source: CERT/CC (VU#213560), via The Hacker News — https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html
This article was generated with AI assistance.