- The £3 Wi-Fi extender provided hidden admin access beyond normal user control.
- Each device running the firmware used the same hidden admin password.
- Changing the visible administrator password failed to disable the secret account.
A £3 Wi-Fi extender bought through Temu has revealed security issues that challenge the idea that cheap connected devices are a bargain.
Security researcher Keiran Smith examined the device and discovered hidden access features that regular users would never see during normal operation.
Smith, who is certified in penetration testing, purchased the six-antenna extender after seeing it advertised through targeted advertising on a shopping app.
Latest videos fromTechRadar
The cheap extender contained access that users couldn’t control
The review started with the hardware, where he identified the MediaTek MT7620 processor, commonly used in low-cost networking products.
After extracting the firmware stored inside the device, Smith discovered a hidden administrator account with full control over its functions.
The account used a fixed password built into the software, meaning every device running that firmware had the same credentials.
Changing the regular admin password through device settings will not remove this individual hidden access.
Smith also found a remote login service that accepted hidden credentials without requiring physical access to the repeater itself.
“It’s worth pinpointing what makes this so bad, because ‘hard-coded password’ covers a wide range of sins,” Smith said.
The researcher said this case was more serious because the password remained the same across all devices rather than being generated individually.
“Default credentials are what the owner can see, what they are being told about, and what they can change,” he said. “What we have here is the opposite on all counts.”
“It is a compile-time constant and not derived from the MAC address or serial number, so it is identical across all devices ever sold.”
The combination of hidden access, unaltered credentials, and remote accessibility creates a security risk for ordinary owners.
Smith found that even if technically experienced users discover the account, the changes may disappear after restarting the extender.
Additional disadvantages raise questions about low-cost connected equipment
The investigation also identified a command injection vulnerability that could allow attackers to execute unauthorized instructions through the device.
Smith discovered that the extender lacked robust software update protection, creating possible opportunities for unauthorized firmware installation.
He acknowledged that these problems do not prove that manufacturers intentionally created insecure features for malicious purposes.
They may have arisen as a result of factory testing and inadvertently remained active until sales to consumers began.
This Temu extender shows how extremely cheap smart devices can create security problems beyond their purchase price.
Consumers can focus on immediate savings without being able to see the software solutions built into connected equipment.
The findings don’t mean that every low-cost network device has the same shortcomings, but they do show why basic security checks are important.
As more homes add connected products, hidden software features may become more of a problem for users and manufacturers.
Via CyberNews
Follow TechRadar on Google News. And add us as your preferred source to get our expert news, reviews and opinions in your feeds.