Cybersecurity researchers at VulnCheck have discovered a factory-installed backdoor, dubbed ENDLESSDOORS, embedded in firmware across at least 20 Zbtlink router models, which automatically beacons to Chinese command-and-control servers and can grant attackers an unauthenticated interactive root shell. The implant, based on an obscure open-source tool called rctl, requires no authentication and can be hijacked by anyone able to intercept or control the C2 domain resolution. Zbtlink has taken down the affected firmware and claims the feature was intended solely for after-sales technical support, but has suspended sales of the impacted models while working on patched firmware.