CERT/CC warns that an unpatched backdoor in multiple Tenda router models grants full admin access without requiring a valid username.