Re: False flag operations
If the backdoor is implemented with proprietary peripheral software (i.e. software that runs on a Wi-Fi card or wired NIC), installing OpenWRT, DD-WRT and FreshTomato won't do anything, as such proprietary OS's include such proprietary software.
It would be feasible with careful design and programming, to include a "feature" in a router, to make it reboot if the Wi-Fi card stops working and then add a "bug" to the Wi-Fi peripheral software, that makes the Wi-Fi card software hang on receiving "interference" on a specific frequency (i.e. from a satellite - ideally that would be within the ~2.4GHz bands, but that doesn't transmit very far through the atmosphere - but specific lower frequencies likely could still be received) and hey presto, the router continuously reboots.
Such backdoor would be easy to keep secret, as Wi-Fi card software is developed in secret by a handful of developers and the source code is not available - only proprietary binaries.
Such backdoor would also be deniable - as decompiling the software wouldn't reveal a obvious backdoor like a backdoor password - such bugdoor would be extremely subtle and be next to impossible to find unless you know exactly what to look for.
Even if you were to capture or find the reboot interference pattern and prove that such "interference" causes the router to reboot, the router company would just apologize for the "bug" and tell you to buy the next model and see if it's fixed (it won't be, there will be more "bugs").
As for routers without wireless interfaces, it'll actually be far easier to implement a similar bugdoor in the wired NIC software that is triggered by specific ICMP packets received over the internet.
In the case of a hardware implant, or hardware backdoor, replacing the OS won't help, although the physical evidence such backdoor are hard to hide from destructive physical analysis techniques, are not deniable when found and are also hard to keep secret from the start (many people on the production line need to know).
Intel for example hasn't implemented any hardware backdoors, but how anyone could login to the intel ME without a password, was definitely a honest mistake and not a bugdoor.