Zbtlink routers ship with factory backdoor implants

Chinese-made Zbtlink routers sold worldwide, often under rebranded and white-label names, have been found to ship with factory-installed backdoors that grant unauthenticated remote root access to anyone who can hijack their command channel.[5][6][9][13] The primary implant, dubbed ENDLESSDOORS, is tracked as CVE-2026-66747 and affects at least twenty consumer and small-business router models used in homes and critical infrastructure networks.[1][7][13][15]

Researchers at VulnCheck say the ENDLESSDOORS component is baked directly into the firmware of Zbtlink devices from Shenzhen Zhibotong Electronics, starting automatically at boot via an init script and persistently phoning home to a remote command-and-control server every few dozen seconds.[7][13][15] The vulnerability has been assigned a critical CVSS score of about 9.3 on the emerging CVSS 4.0 scale, reflecting the combination of remote reachability, lack of authentication, and full device takeover, while other analyses using CVSSv3 rate related flaws at 9.8.[1][2][4][14] Public vulnerability databases and industry research notes now list CVE-2026-66747 as a factory-shipped backdoor rather than a conventional software bug, underscoring concerns about supply-chain integrity.[1][6][14]

The affected hardware is not limited to Zbtlink-branded units; VulnCheck and other outlets report that the same firmware images are used across more than twenty router and CPE models, including the CPE2801, WE and WG series, and dual-SIM 4G/5G gateways, many of which are sold under OEM and white-label brands on major global e-commerce platforms.[5][7][8][10] Analyses of every firmware image available from Zbtlink’s download portal found the ENDLESSDOORS client embedded and enabled by default, with no user-facing indication that the router is maintaining a permanent remote-access channel.[13][15] Because the implant’s network protocol lacks encryption and robust server verification, anyone on the network path between a router and its original command server can intercept or hijack the traffic and obtain a root shell, regardless of how the device is configured.[10][13]

In initial statements, Zbtlink framed the backdoor as an “after-sales technical support tool” meant to simplify remote troubleshooting and configuration for customers, insisting that it should only be used with explicit authorization.[11] Following widespread reporting and criticism, the company suspended sales of affected router models, removed the backdoored firmware from its download site, and said it was developing updates to address the issue, but it has not provided clear timelines or detailed remediation guidance.[6][11] Security researchers and industry observers have questioned why such a powerful capability was deployed without cryptographic safeguards, customer transparency, or robust access controls, particularly in products that are marketed into small-business and industrial environments.[5][6][15]

Concerns deepened after subsequent research revealed that ENDLESSDOORS is not the only hidden access mechanism in Zbtlink firmware. Reuters reported that two earlier backdoors, named Darklantern and Speakingstone, existed on certain router models before ENDLESSDOORS, suggesting a longer-running pattern of factory-installed remote access tools across product generations.[12] While there is no confirmed large-scale exploitation in the wild so far, independent vulnerability write-ups note that similarly critical Zbtlink flaws providing unauthenticated root access have been scored at 9.8 under CVSSv3, and that the lack of basic security controls makes opportunistic abuse straightforward for capable attackers.[2][4][6]

Defenders face a difficult remediation path because ENDLESSDOORS is part of the trusted firmware rather than a removable add-on, and many of the affected routers are deployed in remote or unmanaged locations where patching is rare.[7][13][15] VulnCheck has urged organizations to treat backdoored Zbtlink and OEM-branded devices as compromised by design and to replace them entirely where possible, publishing indicators of compromise, YARA rules, and Suricata/Snort signatures to help detect the implant’s traffic.[10][13] Sector-specific advisories from critical infrastructure information-sharing groups recommend immediate asset discovery to identify Zbtlink-derived hardware, close monitoring for unexplained outbound connections from routers, and the isolation or retirement of suspect units until trustworthy firmware becomes available.[7][8]

References

  1. Factory-Installed Backdoors in Zbtlink Routers
  2. ZBT Router Backdoor Sinkholed by VulnCheck
  3. CVE-2026-66747: Zbtlink Backdoor, Unauth Root RCE
  4. VulnCheck Warns That Chinese Zbtlink Routers Include a Backdoor
  5. Chinese Routers Sold Worldwide Contain Backdoors – Dark Reading
  6. (TLP:CLEAR) Backdoor Identified in Chinese-Made Zbtlink …
  7. ENDLESSDOORS (CVE-2026-66747) — twenty Zbtlink router models ship from the factory with an unauthenticated root-command backdoor, and the discloser’s remedy is replacement
  8. Chinese-made Zbtlink routers have backdoor, researchers say
  9. Zbtlink Routers Found with Backdoor Vulnerability CVE- …
  10. China’s Zbtlink suspends sales of routers found to contain …
  11. Researchers discover additional backdoors in Chinese-made Zbtlink routers
  12. ENDLESSDOORS Is Phoning Home. Pick Up. | Blog
  13. CSAI Foundation | Cloud Security Alliance
  14. Chinese-Made Zbtlink Routers Ship With Backdoor That …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply