AI News Feed
Market watch
Cybersecurity

Researcher Finds £3 Temu Wi-Fi Extender Ships With Hidden Admin Access and Shared Password

A security researcher found a £3 Temu Wi-Fi extender contains a hidden administrator account, a hardcoded password used across units and remote access flaws, according to TechRadar.

The examination began with hardware analysis. Smith identified a MediaTek MT7620 processor, a chip commonly used in low-cost networking products. After extracting the firmware stored inside the device, he found a concealed administrator account that had complete control over the extender’s functions, TechRadar reported.

The hidden account used a fixed password embedded in software, meaning every unit using that firmware carried the same credentials. Changing the normal administrator password through device settings would not remove the separate hidden access, according to the report. Smith also found a remote login service that accepted the concealed credentials without requiring physical access to the extender.

Smith said the nature of the password made the issue more serious than a standard default credential. “It’s worth being precise about what makes this as bad as it is, because ‘hardcoded password’ covers a wide range of sins,” he said. “A default credential is something the owner can see, is told about and can change,” he said. “What we have here is the opposite on every count.” He added that the password was a compile-time constant rather than something derived from the MAC address or serial number, so it was identical on every unit sold.

Even if technically skilled users discovered the account, Smith found that changes could disappear after restarting the extender. TechRadar reported that the combination of hidden access, unchanged credentials and remote availability creates a security concern for ordinary owners.

The investigation also uncovered a command injection weakness that could allow attackers to execute unauthorized instructions through the device. Smith found the extender lacked strong protection around software updates, creating possible opportunities for tampered firmware installation.

Smith acknowledged that the issues did not prove manufacturers intentionally created unsafe features for malicious purposes, TechRadar reported. They could have originated from factory testing processes and remained active accidentally before consumer sales.

The findings do not mean every inexpensive networking device contains similar weaknesses, but they show why basic security checks matter, according to the report. As more homes add connected products, hidden software features could become a larger concern for users and manufacturers.

Editor's Summary

Security researcher Keiran Smith found that a £3 Temu Wi-Fi extender contains a hidden administrator account with a shared hardcoded password, remote login access and other firmware flaws, according to TechRadar. The device’s visible administrator password cannot disable the hidden account, and changes may disappear after a restart. Smith said the flaws could stem from factory testing rather than deliberate malice, but the case underscores the security risks of very cheap connected hardware.