A £3 Wi Fi extender sold through Temu has raised serious security concerns after a security researcher discovered hidden administrator access, shared credentials and other vulnerabilities buried inside the device.
The inexpensive extender might look like an easy way to improve wireless coverage at home, but an investigation into its hardware and firmware suggests that its low price could come with a significant security trade off.
Security researcher Keiran Smith examined the six antenna device after purchasing it through Temu. His investigation uncovered several features that would not be visible to a typical owner using the extender through its standard settings.
The most concerning discovery was a concealed administrator account with extensive control over the device.
Hidden credentials create the biggest concern
Smith began by examining the extender’s hardware and identified a MediaTek MT7620 processor, a chip commonly found in affordable networking equipment.
He then extracted the firmware from the device to investigate how its software worked. That examination revealed administrator credentials embedded directly into the firmware.
The problem was not simply that the device contained a default password.
According to the researcher, the credentials were associated with a hidden account that remained separate from the normal administrator account available through the device’s interface.
That meant an owner could change the visible administrator password without necessarily disabling the concealed access.
Even more concerning, the same password was reportedly used across devices running the same firmware.
In practical terms, this means the security of one extender was not isolated from another. If the hidden credentials became known, other devices using the same software could potentially be exposed as well.
For an internet connected networking product, that is a particularly serious weakness because the device sits between users and the rest of their home network.
Remote access and other flaws add to the risk
The investigation reportedly uncovered a remote login service that accepted the concealed credentials. This raised the possibility of accessing the extender without having physical access to the hardware.
That changes the nature of the problem considerably.
A weak password on a device that can only be reached locally is already undesirable, but a hidden credential that can potentially be used remotely presents a much larger attack surface.
Smith also discovered a command injection vulnerability. Such weaknesses can allow specially crafted input to cause a device to execute commands that were not intended by the manufacturer.
The extender also appeared to have inadequate protection around firmware updates. Poorly secured update mechanisms can create another avenue for attackers if they are able to manipulate software before it is installed on the device.
Taken together, these findings suggest that the security problems extend beyond a single badly chosen password.
They point to deeper weaknesses in the way the device was designed and maintained.
The problem may not have been intentional
There is an important distinction between discovering a hidden access mechanism and proving that a manufacturer deliberately built a backdoor into a consumer product.
Smith did not claim that the findings demonstrated malicious intent.
One possible explanation is that the hidden account and other features were originally created for factory testing, development or servicing. Such mechanisms can sometimes remain in production firmware if they are not removed before products reach consumers.
That does not make the security implications any less important.
A feature created for testing can become a serious vulnerability when it remains active on millions of consumer devices.
The researcher also reported that some changes made by users could disappear after the extender was restarted, making it harder for technically knowledgeable owners to permanently address the problem themselves.
Cheap networking products deserve closer scrutiny
The findings highlight a broader issue with extremely inexpensive connected hardware.
Consumers understandably tend to judge a £3 product by what it does and how much it costs. A Wi Fi extender that appears to work for a fraction of the price of products from established networking brands can seem like an obvious bargain.
Security is much harder to evaluate.
Unlike performance, range or design, weaknesses buried inside firmware are rarely visible when a product is sitting in an online shopping basket.
Networking equipment deserves particular attention because it plays a critical role in a home’s digital infrastructure. An attacker who gains control of a router or extender could potentially use it as a foothold for further attacks, depending on the device’s configuration and the other systems connected to the network.
That does not mean every cheap device sold through Temu is unsafe, nor does the investigation establish that inexpensive networking hardware as a category is inherently dangerous.
It does, however, demonstrate why buyers should be cautious when choosing connected equipment based almost entirely on price.
For consumers who already own an inexpensive extender, checking whether the manufacturer provides firmware updates and whether the device has received security fixes is a sensible first step.
If a product has no clear manufacturer support, no reliable update mechanism and unexplained administrative access, replacing it with a better supported device may be the safer option.
The £3 price tag might look attractive at first glance. But when a networking device contains credentials that users cannot see or remove, the real cost of saving a few pounds could be much higher than expected.
Follow TechBSB For More Updates
