August 2, 2026

Reset button? More like regret button

Rooting, firmware analysis and persistent credentials of TP-Link TL-841N

Cheap router, wild secrets: commenters roast an old bargain box with lingering logins

TLDR: A used budget router reportedly kept old owner login details even after a full reset, raising a basic but important privacy warning for secondhand devices. Commenters were split between shrugging that the router is ancient junk, swapping hobbyist tips, and joking that the real crime was not rewriting it in Rust.

A bargain-bin home router has become the internet’s latest tiny scandal after one tinkerer bought a used TP-Link TL-841N for about $10, cracked it open, and went digging for secrets. The big yikes moment? They say they found plain-text login details from the previous owner still sitting inside the device, including one that could survive a full factory reset. For non-router people: that means pressing the “start over” button may not actually wipe everything you’d expect. Cue the collective shiver.

But the comments didn’t just gasp — they instantly turned this into a full-on community variety show. One camp was deeply unsurprised, basically saying, “Well, yeah, this thing is old, cheap, and running on fumes,” with one commenter noting the 841N is basically end-of-life and famously short on memory. Another group went nostalgic instead, reminiscing about stuffing OpenWRT — a hobbyist replacement operating system for routers — onto the little box and squeezing every last cent of value out of it. The mood was less outrage, more “this crusty gremlin of a router gave us exactly the chaos we paid for.”

Then came the jokes. Someone dropped the classic “should’ve been written in Rust” line, because no internet security thread is complete without a programming-language sermon. Another commenter skipped the drama entirely to recommend a better tool for talking to the device, while someone else bonded over owning the exact same multimeter. In other words: a scary privacy story, a thrift-store gadget autopsy, and a comments section ping-ponging between alarm, nerd tips, and affectionate trash-talk.

Key Points

  • The article documents a hands-on hardware hacking workflow applied to a TP-Link TL-841N(EU) router.
  • The investigation includes UART discovery, two firmware dumping methods, root filesystem extraction, and preliminary filesystem analysis.
  • The author used FCCID documentation and identified the router's flash chip as a GD25Q64CSIG located on the underside of the board.
  • The write-up explains how to identify UART pins and connect a USB-to-UART adapter for serial access, including use of picocom at 115200 baud.
  • The author reports finding plaintext, hardcoded credentials from the router's previous owner, including one that allegedly survives a full reset.

Hottest takes

"pretty much an EOL device with not much flash/ram" — BlackRabbit1
"Clearly the problem is the firmware was not written in Rust" — youareinsuffera
"Eventually it just stopped working altogether, but... i got more than my money's worth" — queenkjuul
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.