The problem with buying ultra-cheap, unknown devices from Temu
You get what you pay for.

Image by Audio und werbung | Shutterstock
- A $3 Temu WiFi extender had a hidden administrator account and remote login enabled by default.
- Ultra-cheap gadgets may lack security testing, software updates, and clear support from a known maker.
- The FBI warned that compromised low-cost devices have powered networks of hacked devices such as BADBOX 2.0.
- Check the manufacturer, update promises, safety record, and app requirements before connecting unknown devices to WiFi.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
When is a bargain literally too good to be true? Probably when it comes from a cheap shopping app with addicting design and some dodgy-looking products.
A $3 WiFi extender sounds like a bargain, particularly if the alternative is spending 10 times as much on a familiar brand. But when penetration tester Keiran Smith cracked open one he had bought from Temu recently, he found something the average buyer would have had no way of spotting.
Buried in the device was a hidden administrator account with the highest level of access, protected by a password hardcoded into its firmware. That meant changing the password shown in the normal settings did nothing to remove it. Remote login was also switched on by default.
There’s no evidence that the access was inserted maliciously – Smith himself suggested it could have been intended for factory testing or support and simply never removed. But it was worrying nonetheless, and shows the perils of ultra-cheap, white-label electronics.
You often have little idea who actually made the hardware or wrote the software – and with that, little idea of how to will fix it if something goes wrong (or what might be miscoded in the first place).
Marketplace, not seller
Temu is a marketplace and not the manufacturer of every gadget sold through it. And while some dangerous devices are more often than not cheap, not every cheap device is dangerous.
However, the economics of producing a device for such a low cost doesn’t allow for the stuff that can make tech secure, like ongoing security testing, software updates and vulnerability handling, all of which require the watchful eye of engineers maintaining firmware years after an item was first sold.
And when you’re putting these gizmos inside your home or business network, those things matter enormously.
In 2025, the FBI warned about BADBOX 2.0, a botnet made up of millions of compromised internet-connected devices including cheap TV streaming boxes, projectors, digital picture frames and aftermarket car infotainment systems.
Some had malicious software installed before purchase while others picked it up in the course of downloading required apps during setup. But regardless of how they became compromised, once connected, they were deployed as residential proxies.
Security researchers at HUMAN, which investigated BADBOX, suggested consumers could have avoided the issue by steering clear of off-brand devices, and relying instead on Google Play Protect certified products.
Hazardous, not hackable
Beyond the risk of being hacked is a more prosaic concern: ultra-cheap gadgets may simply be unsafe. In May, the European Commission fined Temu €200 million for failing to adequately assess the risk of illegal products appearing on its platform.
Mystery shoppers sent out by the EU found a “very high percentage” of chargers bought failed basic safety tests. Temu said the fine related to its 2024 risk assessment, rather than the current systems it has in place, and that it had since strengthened its protections.
In the UK, connected consumer products sold since April 2024 are supposed to meet baseline security rules that include protections against easily guessed default passwords and a disclosure of how long security updates will be provided to consumers who buy the product.
The National Cyber Security Centre recommends checking both before buying, then enabling automatic updates and 2-factor authentication where available – though at the lower end of the market, that often doesn’t happen.
However, it doesn’t mean that consumers have to accept that state of affairs. We have a role to play, too, and power to exert to make marketplaces offer better services.
So before connecting something to your WiFi, check whether you can identify the manufacturer, whether it has a real support website, how long updates are promised, and whether independent researchers have examined the model.
And if a suspiciously cheap Android box asks you to disable Google Play Protect or install software from an unofficial app store, stop. Because the bargain might not be that much of a bargain if your entire network ends up bricked, or even worse, hacked.