Particle.news

Zbtlink Routers Ship With Built‑In Backdoor That Can Grant Unauthenticated Root Shells

Researchers say the implant phones home to hardcoded Chinese servers to enable remote execution of root commands, leaving deployed devices worldwide exposed.

Overview

  • Cybersecurity firm VulnCheck reported on Thursday that every one of the 21 Zbtlink firmware images available on the vendor site across more than two years contains an implant called ENDLESSDOORS that starts at boot.
  • The implant is a customized version of a small open‑source tool called rctl that beacons outbound to a short list of Chinese‑hosted command servers as often as every 35 seconds and accepts commands with no authentication.
  • VulnCheck demonstrated that a reserved command can force the router to open an interactive root shell, which means anyone who controls or hijacks the C2 endpoints can run arbitrary root commands on affected devices.
  • Zbtlink has removed the affected firmware downloads and says engineering teams are developing security‑validated patches, but researchers warn deployed units remain vulnerable and advise replacement or strict egress isolation until fixes are verified.
  • The case highlights wider supply‑chain risks because the same Zbtlink hardware is often rebadged and supplied by ISPs, making detection harder for end users and raising broader national security concerns in Western countries.