Breaking Bad Routers: 6 Vendors, 6 Shells, 0 Days
by MrBruh | - 2:30pm
I started 2026 with a simple question: are consumer routers actually secure? To find out, I audited firmware from six major vendors, and the results were worse than expected.
This research yielded 28 distinct vulnerabilities across the board, culminating in Remote Code Execution (RCE) against every vendor I tested, including TP-Link, Netgear, Linksys and Motorola.
In this talk, I’ll cover the discovery of these vulnerabilities, the disclosure process for each, and their overall impact.
About MrBruh
My name is Paul, though I am better known online by my alias, ‘MrBruh’. I am a 22-year-old independent, self-taught cybersecurity researcher. In just over a year, I have discovered 37 vulnerabilities in widely used software and hardware, with the majority leading to remote code execution. My findings include flaws in products from major tech companies such as AMD, ASUS, Google, Linksys, Motorola, MSI, Netgear, and TP-Link.