{
  "id": 213575,
  "title": "Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway",
  "url": "https://urgent.news/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-213575",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-06T04:57:43.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/5283794"
  },
  "original_language": "en",
  "account": "Chinese router manufacturer Zbtlink has vehemently denied accusations from threat intelligence provider VulnCheck that its products contain backdoors. VulnCheck's CTO, Jacob Baines, claimed that a Zbtlink router in his possession \"continuously attempts to reach a command and control server on the internet\" and named the backdoor \"ENDLESSDOORS.\" The alleged backdoor utilizes a simple command and control client and server, implemented in a small tool called rctl and uploaded to GitHub in January 2015.\n\nDespite Zbtlink's spokesperson asserting that the code was intended solely for after-sales maintenance and would not be included in mass-production shipments, the company has temporarily paused firmware downloads as a precautionary measure. The company claims that their customers typically use their own self-developed software instead of ZBT's default firmware.\n\nVulnCheck contends that the devices tested by the company only phone home to four endpoints, with one endpoint connected to Zbtlink. The organization's CTO labeled this connection \"damning,\" as it potentially enables unauthorized control of the affected routers. Zbtlink's download page mentioned the backdoor issue, but the company's spokesperson maintained that the problem was unrelated to security vulnerabilities.\n\nThe Register noted that router firmware could be an attractive target for supply chain attacks, and Baines' decision to disregard responsible coordinated disclosure was based on the belief that the behavior was not an intentional design choice. To counter the threat posed by potentially infected devices, VulnCheck recommended implementing rules to block access to the compromised endpoints, as well as employing stricter egress controls to prevent unauthorized communication.",
  "summary": "It’s just a remote maintenance function, says Zbtlink",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway",
        "url": "https://urgent.news/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but",
        "published": "2026-08-06T04:57:43.000Z"
      },
      {
        "outlet": "TechRadar",
        "title": "Another top router maker accused of firmware having backdoors — Chinese giant Zbtlink halts downloads to fix issue",
        "url": "https://urgent.news/2026/08/06/another-top-router-maker-accused-of-firmware-having-backdoors-chinese",
        "published": "2026-08-06T15:15:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}