The Router Is Not a Passive Device - It's the Attack Surface

TL;DR AI
2 min readKey summary
Internet-exposed routers with default credentials and unpatched firmware were found vulnerable to a high-severity flaw.
CVE-2025-6843 used a hardcoded backdoor to bypass authentication, enabling remote access, command execution, and data exfiltration.
Red team testing reproduced the issue on off-the-shelf devices such as TP-Link Archer C7 v5 and Netgear R6400.
Many affected routers remained unpatched and largely undetected, leaving them open to abuse.
The case shows unmanaged network hardware can become a silent entry point without asset inventory, monitoring, and configuration enforcement.

