Discussion summary
Recent discussions highlight concerns about hidden backdoors in Tenda firmware across multiple versions, raising security and ethical questions.
What the discussion says
- Many users believe backdoors are common in consumer electronics.
- Some suggest Chinese companies are more prone to such practices.
- US and Israeli companies have also been implicated in backdoor concerns.
“Almost all consumer electronics come with backdoors—especially given the prevalence of computational advertising.”
“This must have been some sort of stupidity… if they tried to build in some backdoor, they would have done it differently…”
Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- A quick search reveals several other serious vulnerabilities in Tenda routers that could grant administrator privileges. Therefore, I tend to believe this is due to the company's incompetence and lack of technical skill rather than malicious intent—but it's still a reason to avoid using Tenda products. There's a reason why Tenda's market share is far lower than TP-Link's.by chirsz
- Most of the software is this way, it seems. Military intelligenece in our country were recently changing configs on peoples routers without their knowledge or consent to get rid of similarly dangerous thing on several types of tp-link routers.
And if you ever looked inside the firmwares of these IoT Linux boxes (be it sip phones, payment terminals, ip cameras, routers, modems, etc.) you'd not want it anywhere near anything that needs to be secure. OpenWRT or your own thing, or very strict isolation, or nothing.
by megous - It looks like recent Tenda hardware/firmware is encrypted per below examples, making it harder to audit.
binwalk US_AC10V6.0si_V16.03.62.09_multi_TDE01.bin
binwalk US_BE12ProV1.0mt_V16.03.66.23_TD01.binDECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 516 0x204 OpenSSL encryption, salted, salt: 0x436999A39FECA649
The third attempt I tried was unencrypted, and possibly reveals the problem exists on another model this CVE doesn't list as affected:DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 516 0x204 OpenSSL encryption, salted, salt: 0x81235B7D4130B6ABbinwalk US_W18EV2_kf_V16.01.0.20\(4766\)_HighPower\ \(1\).bin
Inside is /squashfs-root/webroot_ro/default_ac.cfg which offers:DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 64 0x40 uImage header, header size: 64 bytes, header CRC: 0x95335734, created: 2026-06-16 09:09:35, image size: 2159135 bytes, Data Address: 0x80100000, Entry Point: 0x805F41C0, data CRC: 0x5ABEDB00, OS: Linux, CPU: MIPS, image type: OS Kernel Image, compression type: lzma, image name: "MIPS Tenda Linux-4.14.90" 128 0x80 LZMA compressed data, properties: 0x6D, dictionary size: 8388608 bytes, uncompressed size: 6947248 bytes 2159263 0x20F29F Squashfs filesystem, little endian, version 4.0, compression:xz, size: 8971644 bytes, 847 inodes, blocksize: 1048576 bytes, created: 2026-06-16 08:53:20
And /squashfs-root/webroot_ro/default_router.cfg which offers:sys.rzadmin.username=rzadmin sys.rzadmin.password=cnphZG1pbg== (ed: base64 decoded: rzadmin) sys.guest.username=guest sys.guest.password=Z3Vlc3Q= (ed: base64 decoded: guest)
From what I can see quickly (I haven't looked hard), "sys.rzadmin.password" is only referenced from the login() function of /bin/httpd in the context of retrieving a value. This value is retrieved and compared before the error message "login err: password is wrong." is emitted. I can't find any other reference to code in any part of the firmware that may allow a user to change the default value of "sys.rzadmin.password".sys.rzadmin.username=rzadmin sys.rzadmin.password=cnphZG1pbg== (ed: base64 decoded: rzadmin)Also for fun there is a function imsd_upload_log_v1 in /bin/imsd that collects SSIDs, MACs, IP addresses, sys.admin.username, sys.rzadmin.username, timezone, and another function imsd_remote_pwd_get in /bin/imsd that retrieves sys.admin.password. Related library /lib/lubucapi.so also looks like a fun binary to inspect more closely as it contains a command set that seemingly allows either cloud management of Tenda routers and/or remote debugging, and possibly is why imsd_remote_pwd_get exists in /bin/imsd
by dhx - My ifconfig is simple: if it's made in Shenzhen, throw it outby matltc
- Yikesby riskd
- I bet more than half of components in all your electronics are made in Shenzhenby hathym
- The US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!by HDBaseT
- They'll have a lot of work to do, if they want to catch up with the amount and rate of "hidden authentication backdoors" all those companies (and also Cisco) have. E.g. https://www.thestack.technology/cisco-hard-coding-passwords-...by k_g_b_
- Not sure if you're joking, but both have already done so. And any US company is subject to secret orders forcing them to implement a backdoor if demanded.
- There was a meme going round of a network diagram that layers a Chinese firewall behind a US firewall behind a Russian firewall so they can all block each other countries backdoors.by Gigachad
- Have used their travel wifi product back when hotel wifi was a strange beast. Wouldn't expect to need it now eSIM and ubiquitous internet travel pricing means the hotel wifi may be the LEAST valid path to access things.
I have a free give-away mikrotik unit in the same price bracket (literally free: they were both conference give-aways) it's physically smaller and it runs what appears to be their mainline code. Say what you like about microtik for quality, they provide pretty much every knob and frob you could want.
by ggm - I’m working on a hotel right now. And I’ve gone to great lengths to make the wifi more secure. Everyone on their own VLAN. Separate PPSK for each room. Credentials are randomly generated and not some ridiculous pattern of last name and room number or similar. We built our own custom access control system, with what at the time was the strongest keycards we could find (mifare desfire ev3), I’m really trying to make a hotel who’s security isn’t such a joke.
- And this is why I handroll my own routers/firewalls, using commodity hardware and a Linux distribution.by drnick1
- Looking to do this to get off stock isp leased router. What's your hardware/distro rec?by matltc
- Tenda has good support among OpenWRT.by SuperMouse
- Man, I remember doing this in the late 90s with ipchains as the only way to get a router that didn't cost an arm and a leg. Eventually consumer/prosumer routers came out.
What's old is new again.
by ikidd - Oh this is amazing! I have a few of their cube routers sitting around and I always hated how app-locked their firmware was when it really is just a wifi repeater with a few extras (mesh) on top. Root access will do wonders to bypassing the app now (and also disabling their ping-for-green-light mechanism which spams the network with a constant dns resolution to microsoft.com lol).
Also honest take this looks less like a "backdoor" (implies malicious - this is a link to a CVE after all) and more like a developer access credential/default credential that was burned into the firmware (i'd imagine the code remains but on a production run they randomize the key so its non-guessable but then you get lazy and dont run that extra step and this slips in/you burn the bare firmware with no production configs).
by Fabricio20 - why would a consumer device need a randomized password?by tinyhitman
- Yes, it is randomized but due to a quirk in the universal probability waveform it always randomizes to 'rzadmin'. Scientists are baffled.by idiotsecant
- The consistency with which networking hardware companies produce such garbage is crazy.
And it’s always amateur hour backdoors somehow. If it was something sophisticated they might get a pass on „ok some security agency made them do it probably“
by Havoc - Sad truth is that too few customers pay extra for proper security. And even then it is questionable will you get it.by Ekaros
- They didn't produce garbage by accident. They followed a plan and made a decision.by daneel_w
- Or the amateur hour backdoors are those that are found.
Or the amateur hour backdoors are there to be found.
by KingOfCoders - > The associated username is not validated, so any provided username will succeed when paired with the backdoor password.
Great. I am really wondering why should the customers trust these manufacturers.
At this point I would not use any router with vendor-provided black box firmware. Full stop.
I would always install OpenWRT or something similar on it before using it.
And if that is not possible for whatever reason, I would not even think about buying such a device.
by pbasista - good approach, but your security should not depend on your router anyway, you should be immune to attacks from itby rootatixww3
- Hm, do you ever go over 1gbit? If my understanding is correct, good affordable routers like Mikrotik's CCR2004 are fully closed, so the only option is to build your own shitty box which will be much less energy efficient than their specialized switch chips.by pshirshov
- Last time when I looked OpenWRT was unable to support MIMO and beamforming capabilities of many of the devices it was running on.
This capabilities are crucial to have decent coverage, signal strength and throughput where I live (i.e.: crowded/congested wireless networks in an apartment complex).
Did OpenWRT team managed to work around them, or did the manufacturers started to play nicer with open drivers with loadable firmware?
by bayindirh - > Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment.
I was unfamiliar with Tenda.
> Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile )
Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have no idea if Tenda does this, I've just seen it previously. Specifically with security cameras)
I wish the authors provided some method for checking this vulnerability other than fw version. It seems like Tenda could just change the password and say "yep! all safe now"
by fusslo - It is probably just a brand, like many others, and based on a reference design from the OEM.
I have a small Tenda 5-port gigabit dumb switch. It uses the same switch chip as this TP-Link, just with different branding; even the "SG105" model number is the same:
https://goughlui.com/2022/02/27/unbox-teardown-tp-link-tl-sg...
by userbinator - I’m in the USA and have a Tenda WiFi usb stick. Not as popular as other brands but they are around