Millions Of Tenda Wi-Fi Routers Exposed By Hidden Backdoor Security Flaw
Unless vulnerable users disable remote web management on the router, this vulnerability can even be exploited remotely. On a local network, options to reduce vulnerability are more limited, with CERT noting that changing your LAN IP address may help but won't protect from deliberate or targeted network scanning. While CERT did attempt to contact Tenda ahead of the vulnerability disclosure, it notes that it was "unable to reach the vendor."

Since the issue is present in firmware, it should be addressable with an update. But because CERT was unable to reach Tenda, it's unclear whether or not Tenda is even aware that the vulnerability has been discovered.
However, its undocumented presence suggests that Tenda could have put it there as an intentional backdoor, which paints the FCC ban on new overseas-manufactured routers in a new light. Tenda Technologies is a Chinese brand, and there's a non-zero chance that such a backdoor was mandated by the CCP.
Even if the backdoor's presence was unintentional, it's certainly a bad look for Tenda. Wireless routers in general have been a sought-after target lately, with the notorious AirSnitch attack targeting virtually all of them.
If you happen to own a Tenda router, you'll want to verify whether or not this issue impacts you. The easiest way to test is to attempt to use the backdoor yourself by typing the reported "rzadmin" password on the login page.
Otherwise, per Slashgear, impacted Tenda routers include the Tenda AC10 AC1200, Tenda AC5 AC1200, and the Tenda AC6 AC1200. CERT also lists six firmware versions known to be affected. We'd advise caution against any Tenda router until updates are released that address the issue, though, since its undocumented, many more models may be affected.