Urgent.News

What's breaking now, across thousands of outlets.

Tech

Biggest backdoor yet found in Chinese routers sold under multiple brand names

The most blatant security backdoor yet seen in an internet router has been found in a range of models sold under multiple brand names. A firmware implant phones home to cloud servers in China to ask for instructions, and can then be remotely controlled …

Biggest backdoor yet found in Chinese routers sold under multiple brand names

A significant security backdoor has been discovered in Chinese routers under various brand names, potentially posing a national security risk. The implant, dubbed ENDLESSDOORS, allows remote control of infected devices through cloud servers in China. Researchers found the zero-day threat in routers made by Shenzhen Zhibotong Electronics and sold under brands such as Zbtlink and Wiflyer.

The backdoor operates on a simple command and control client server, listening on port 7000 for connections. This allows the router to initiate contact with its command servers, bypassing any need for internet reachability. The connection traverses NAT and egress filtering, making it as accessible as any other outbound TCP session.

The researchers advise replacing any affected models, including CPE2801, WE1026-5G-WD, and WG3526, among others.

Written by urgent.news from 9to5Mac's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at 9to5mac.com →

More in Tech

More from Thursday 6 August →