← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

Zbtlink Routers Found with Factory-Shipped Backdoor, Codename ENDLESSDOORS

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Backdoor found in at least 20 Zbtlink router models.
  • Implant present in all 21 firmware images over two years.
  • Backdoor, ENDLESSDOORS, is a customized 'rctl' tool.
  • Establishes unauthenticated root shell and beacons to C2.
  • Sold under Zbtlink, Wiflyer, and other brands.

Discovery of Router Backdoor

Cybersecurity firm VulnCheck has identified a "factory-shipped backdoor" in at least 20 router models manufactured by Zbtlink. This implant, dubbed ENDLESSDOORS, is present in all 21 firmware images currently available from Zbtlink, spanning more than two years of releases.

Technical Details of ENDLESSDOORS

ENDLESSDOORS is a customized version of a small tool called 'rctl' (remote control linux). This tool, originally uploaded to GitHub in 2015, implements a command and control client and server. The server listens on port 7000 and can send shell commands or instruct the client to spawn a reverse bash shell.

The backdoor masquerades as a Linux kernel thread but operates as a userland process with root privileges. It attempts to beacon to Chinese command-and-control (C2) infrastructure as frequently as every 35 seconds, allowing for remote control of the affected devices.

Affected Devices and Brands

The routers containing the ENDLESSDOORS backdoor are manufactured by Shenzhen Zhibotong Electronics and are sold under various brand names, including Zbtlink and Wiflyer. The challenge in identifying affected devices is compounded by the practice of rebadging and reselling these routers under different brands, sometimes with misleading countries of origin.

Security Implications

This backdoor poses a significant security risk as it allows for unauthenticated root access and remote control of the routers. By initiating contact with cloud servers in China, the implant bypasses typical network defenses that monitor incoming connections. The US government previously banned the import and sale of new Chinese router models due to national security concerns, following incidents involving compromised routers from other manufacturers.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Cybersecurity firm VulnCheck discovered a backdoor, dubbed ENDLESSDOORS, in routers manufactured by Shenzhen Zhibotong Electronics and sold under various brands like Zbtlink and Wiflyer. This backdoor initiates contact with cloud servers in China, allowing remote control and posing a significant security risk because it bypasses typical network defenses by dialing out from the internal network.

Cybersecurity researchers at VulnCheck discovered a "factory-shipped backdoor" in at least 20 Zbtlink router models, present in all 21 available firmware images over two years. This backdoor, codenamed ENDLESSDOORS, is a customized version of the 'rctl' tool that establishes an unauthenticated root shell and beacons to Chinese command-and-control infrastructure, posing a significant security risk to users.