152
people found this helpful, as of 2023
ranked #209,122 most helpful
out of 571,544,897 reviews
★☆☆☆☆
DO NOT buy this brand. Seriously. MAJOR security holes
I won't even lie. This router worked great for me - strong signal, fairly insane speeds; I was getting 75mbps down (5GHz channel) and I'm pretty sure I only have a 30mbps Comcast plan. Good admin interface, everything checks out, and the price sure was right.
But some vulnerability/backdoor (specifically something IPV6-related, as I noticed lots of strange traffic through that, and I normally never used ipv6 previously) got my ENTIRE house full of computers infected with a Windows Management Instrumentation (WMI) related malware, where the attacker remotely modified my Windows installation to be set up as an Active Directory client, as if my PC thought it was on a corporate network, beholden to the IT administration's control. So my group policies almost all set themselves to "Managed", and I couldn't change them myself. It also spread itself to any new USB media I made with windows' official Media Creation Tool, I believe through auto-generated malicious autorun.inf's under invalid pathnames, like D:\System Volume Information\:\:autorun.inf (windows doesn't allow colons in pathnames), among many other weird and not-easily-detectable signs of tampering in my machine. Before I even noticed something was amiss, it had taken control of all the other PCs in the house including my girlfriend's. Even after a full drive wipe on any given computer, the malicious presence remained in the background.
Just google "Tenda vulnerability", specifically Loki Labs' article "Tenda, is this a bad design or a backdoor?" to see what I'm talking about. Also read up on WMI malware, such as the recent Astaroth malware which I think might've been part of the type of virus I acquired, and how notorious and ancient it is as a method to compromise computers remotely. If you buy+use this router for a few days it's likely you'll even pick up a remote attacker on your network and not be able to notice it, except for some innocent-looking COM Surrogate Provider, rundll.32, Font Caching etc. (the list goes on and on) processes that blend in entirely with the operating system, because they are built-in to it. You'd be surprised just how insidious this type of infection can be, especially if you try to remove it without locking down your home network security impeccably before starting the reinstalls and everything.
I've been tinkering with computers since I was almost a baby; develop software for a living and I've never seen anything quite like this until now. I'm still trying to get rid of it completely, after 2+ weeks of late nights and headaches, thinking I might've vanquished it this time only to find another subtle but unmistakable sign of infection. I've obviously ripped this router out and am preparing to return it, using my old wireless-N router for the moment, but even still this stupid attack seems to persist on all my computers, even on Ubuntu/linux (!!!), as I believe it got access to some of my laptops' UEFI firmware somewhere along the way... it's terrible, trust me, just don't mess with the Chinese brands if you value your time and privacy. I never cared either until this incident but you can bet your butt I have learned my lesson, firmly.
May 2020 · Electronics · verified purchase