Researchers Found Hardcoded Passwords in Temu WiFi Extender
A security audit revealed that a low-cost WiFi extender purchased on Temu contained a hidden administrator account.
Updated on Oct. 7, 2026 in Cybersecurity

Live Poll
Is buying ultra-cheap electronics from discount marketplaces worth the security risk to your home network?
Security researchers discovered that a $3 WiFi extender purchased from Temu contained a hidden administrator account with a hardcoded password. The device also had remote login enabled by default, creating a significant vulnerability for users.
Why it matters
Low manufacturing costs often lead producers to bypass essential security testing and software updates for connected devices. This case highlights the risks consumers face when purchasing inexpensive electronics that lack basic cybersecurity safeguards.
The tested device featured a hardcoded password embedded directly into its firmware that prevented users from effectively changing administrative credentials. Additionally, the unit came with remote login functionality enabled by default.
The players
Temu
Temu is an online marketplace that connects consumers with manufacturers and was recently fined for failing to manage risks of illegal products.
European Commission
The European Commission is the executive branch of the European Union responsible for proposing legislation and enforcing regulations across member states.
FBI
The Federal Bureau of Investigation is the domestic intelligence and security service of the United States.
The details
The WiFi extender was found to contain a hidden administrator account that remained active even if users attempted to set their own credentials. Compromise of such devices often occurs during the required app download phase of the initial setup process.
Timeline
UK security regulations for connected products took effect in April 2024.
The FBI issued warnings regarding the BADBOX 2.0 botnet in 2025.
The European Commission issued a €200 million fine to Temu in May 2026.
The Tech Race
The emergence of these vulnerabilities tests the reach of the UK baseline security rules for connected products, which aim to mandate minimum safety standards for consumer hardware. This discovery demonstrates a potential challenge in enforcing compliance against international vendors.
Users of inexpensive smart home devices may inadvertently expose their home networks to unauthorized remote access. Consumers should prioritize products from verified manufacturers that offer clear support for firmware updates and security patches.
The takeaway
When purchasing budget electronics, consumers should be aware that lower production costs often come at the expense of critical security protocols. Verify that any connected device allows for the complete removal of default credentials before connecting it to a home network.
Further reading
Learn more about modern digital threats in our Cybersecurity section.
Source note: This article includes information reported by Cybernews.
Live Poll
Is buying ultra-cheap electronics from discount marketplaces worth the security risk to your home network?







