Another top router maker accused of firmware having backdoors — Chinese giant Zbtlink halts downloads to fix issue
The company denied allegations but still moved to address them by restricting firmware downloads for 20+ models.
Chinese router manufacturer Zbtlink is under scrutiny for allegedly shipping its devices with a built-in backdoor known as "ENDLESSDOORS." According to Jacob Baines, CTO of cybersecurity firm VulnCheck, the router continuously attempts to reach a command-and-control server on the internet, seeking root commands and reverse shells. The vulnerability, discovered and documented by VulnCheck researchers, is present across roughly two dozen firmware images on Zbtlink's download page.
Zbtlink denied any malicious intent, claiming the feature was meant for after-sales maintenance and was only present on sample units for debugging purposes. However, Baines argues that the assumption of intended behavior does not hold in this case. Upon testing, VulnCheck successfully exploited the vulnerability, confirming its presence in all firmware versions.
In response, Zbtlink claimed the company mischaracterized the code, stating it is solely for after-sales maintenance and will not be included in mass-production shipments.
Researchers have warned that all firmware images are potentially hijackable, advising users to replace devices or implement strict egress controls. Zbtlink has temporarily removed the impacted firmware versions from download channels and is working on a secured patch. Baines advises that for devices carrying real traffic, users should either replace the device or move it behind strict egress control measures, treating the LAN as untrusted.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.