The flaw your router is being hacked through was fixed in 2021
CVE-2021-35394 is five years old. It sits in the Realtek Jungle SDK, a lump of software that dozens of manufacturers built into routers, access points and recording boxes without ever writing it themselves. It was patched in 2021. Plenty of the hardware in people's homes never received that patch, and attackers know it.
Nozomi Networks Labs went looking at a surge in attempts against that flaw and found a botnet nobody had named yet. They are calling it Cling. The sample they pulled apart carries exploits for eight separate vulnerabilities, reaching beyond Realtek gear into LB-LINK and Linksys routers, Eir and FiberHome boxes, and TBK and MVPower CCTV recorders. Once in, it copies itself to a couple of hidden locations, hooks itself into the device's startup files so a reboot does not shift it, and even swaps out the wget command so the device fetches what the operator wants.
The clever part is how it takes orders. Every five seconds or so it pings 13 public STUN servers, the ordinary machines that video calls use to work out how to reach each other through a home connection. Replies appear to come from Google. They do not: the address is spoofed, and the command is tucked inside a field that should hold a random identifier. To a network it looks like somebody on a video call. What it can actually do is scan, tunnel, relay traffic and join denial-of-service floods.
Nothing on your PC will show this. The device is the victim and it has no screen. Check the manufacturer's site for firmware for your exact model, switch off remote management from the internet if it is on, and treat a router that stopped getting updates years ago as something to replace rather than keep. Tendvane's network scan lists what is actually connected to your home network, which is usually the moment people remember the camera in the hallway.