Chinese router vendor Zbtlink has denied that its firmware contains backdoors, claiming a suspicious remote-control feature found by security firm VulnCheck was intended solely for after-sales maintenance on sample units. However, the company simultaneously paused firmware downloads and acknowledged unspecified security vulnerabilities, contradicting its denial. VulnCheck's CTO described the code as a persistent, boot-loaded implant across more than 20 router models that phones home to external servers with no authentication, allowing anyone controlling those endpoints to issue commands to affected devices.