Hidden backdoor found in over 20 Chinese-made wireless router models amid US security concerns

A cybersecurity firm has uncovered a hidden backdoor in more than 20 models of Chinese-made wireless routers, intensifying Western scrutiny over the security of network devices from Chinese manufacturers and highlighting potential risks to global networks.

A cybersecurity firm has identified a hidden backdoor in more than 20 models of Chinese-made wireless routers, a finding that adds to long-running Western concerns about the security of network gear built by Chinese manufacturers. VulnCheck said the flaw, which it has dubbed “Endlessdoors”, affects devices made by Shenzhen Zhibotong Electronics and sold under the Zbtlink and Wiflyer names. Jacob Baines, the company’s chief technology officer, said the issue could allow unauthorised access to routers that sit at the centre of home and office networks.

According to Baines, the vulnerability is not limited to a single brand label. He said the same hardware can be sold through different companies under original equipment manufacturer and original design manufacturer arrangements, making model numbers more important than the name on the front of the box. VulnCheck said it has identified at least 100,000 deployed devices and warned that the backdoor automatically tries to reach a fixed set of remote endpoints. If those domains were controlled by hostile actors, they could potentially take over the router and move deeper into connected devices on the same local network.

The discovery lands at a time of heightened scrutiny of Chinese networking equipment in the United States. In March, the Federal Communications Commission said it was restricting imports of certain foreign-made consumer routers, arguing that such devices had been used by malicious actors to target American households, disrupt communications, carry out espionage and steal intellectual property. The FCC also linked foreign-made routers to cyber campaigns including Volt Typhoon, Flax Typhoon and Salt Typhoon. Separately, Texas sued TP-Link Systems in February, alleging the company exposed consumer devices to access by the Chinese government. TP-Link rejected the claims and said it would “vigorously defend” its reputation.

VulnCheck urged organisations to check whether any of the affected models remain in use, naming CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526 and Z8102AX-2DSIM. The disclosure also comes against a broader backdrop of similar router security warnings. In July, CERT/CC said several Tenda models contained an undocumented authentication backdoor that could hand full administrative control to an attacker, underscoring how router flaws can expose entire networks when vendors fail to patch them quickly.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.