Biggest backdoor yet found in Chinese routers sold under multiple brand names
The most blatant security backdoor yet seen in an internet router has been found in a range of models sold under multiple brand names. A firmware implant phones home to cloud servers in China to ask for instructions, and can then be remotely controlled …
A significant security backdoor has been discovered in Chinese routers under various brand names, potentially posing a national security risk. The implant, dubbed ENDLESSDOORS, allows remote control of infected devices through cloud servers in China. Researchers found the zero-day threat in routers made by Shenzhen Zhibotong Electronics and sold under brands such as Zbtlink and Wiflyer.
The backdoor operates on a simple command and control client server, listening on port 7000 for connections. This allows the router to initiate contact with its command servers, bypassing any need for internet reachability. The connection traverses NAT and egress filtering, making it as accessible as any other outbound TCP session.
The researchers advise replacing any affected models, including CPE2801, WE1026-5G-WD, and WG3526, among others.
Written by urgent.news from 9to5Mac's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.