← BACK TO FEED
TAG

backdoor2 articles

Chinese Router Maker Says Its Firmware Backdoor Is Fine, Actually, Then Quietly Pulls Firmware

Chinese router vendor Zbtlink has denied that its firmware contains backdoors, claiming a suspicious remote-control feature found by security firm VulnCheck was intended solely for after-sales maintenance on sample units. However, the company simultaneously paused firmware downloads and acknowledged unspecified security vulnerabilities, contradicting its denial. VulnCheck's CTO described the code as a persistent, boot-loaded implant across more than 20 router models that phones home to external servers with no authentication, allowing anyone controlling those endpoints to issue commands to affected devices.

11 Aug 2026

Zbtlink Routers Shipped With Built-In Backdoor Handing Out Root Shells to Anyone Listening

Cybersecurity researchers at VulnCheck have discovered a factory-installed backdoor, dubbed ENDLESSDOORS, embedded in firmware across at least 20 Zbtlink router models, which automatically beacons to Chinese command-and-control servers and can grant attackers an unauthenticated interactive root shell. The implant, based on an obscure open-source tool called rctl, requires no authentication and can be hijacked by anyone able to intercept or control the C2 domain resolution. Zbtlink has taken down the affected firmware and claims the feature was intended solely for after-sales technical support, but has suspended sales of the impacted models while working on patched firmware.

10 Aug 2026