← BACK TO FEED
TAG

iot2 articles

Chinese Router Maker Says Its Firmware Backdoor Is Fine, Actually, Then Quietly Pulls Firmware

Chinese router vendor Zbtlink has denied that its firmware contains backdoors, claiming a suspicious remote-control feature found by security firm VulnCheck was intended solely for after-sales maintenance on sample units. However, the company simultaneously paused firmware downloads and acknowledged unspecified security vulnerabilities, contradicting its denial. VulnCheck's CTO described the code as a persistent, boot-loaded implant across more than 20 router models that phones home to external servers with no authentication, allowing anyone controlling those endpoints to issue commands to affected devices.

11 Aug 2026

Seven Unpatched Flaws in a Tiny Filesystem Library Put Millions of Embedded Devices at Risk

Security researchers at runZero have disclosed seven vulnerabilities in FatFs, a widely used filesystem library embedded in millions of devices including security cameras, drones, industrial controllers, and crypto wallets. The most serious flaws can allow an attacker with physical access — such as inserting a malicious USB drive or SD card — to corrupt device memory and execute arbitrary code, with no upstream fixes available for six of the seven bugs due to an unresponsive maintainer. The situation is compounded by the fact that runZero used an AI-assisted fuzzing pipeline to discover the flaws, meaning the barrier to exploitation is low, while downstream vendors face a potentially years-long patching process with no coordinated disclosure channel in place.

8 Jul 2026