Security researchers have discovered a covert remote-control backdoor embedded in nearly two dozen consumer routers sold under Zbtlink and Wiflyer branding, potentially endangering over 100,000 devices globally and raising alarm over hardware trust and security.
Security researchers have uncovered a hidden remote-control backdoor in nearly two dozen consumer routers sold by Chinese maker Zbtlink, with the implant apparently built into the devices rather than added by outside attackers. VulnCheck says the threat, which it has named Endlessdoors, affects routers sold under Zbtlink and Wiflyer branding, as well as white-label versions sold through other channels, and could put more than 100,000 units in circulation worldwide at risk.
According to VulnCheck CTO Jacob Baines, the backdoor checks in to a command-and-control server every 35 seconds over cleartext TCP, then accepts instructions that can be turned into full root access on the device. VulnCheck has assigned the issue CVE-2026-66747 and given it a severity score of 9.3, describing it as a critical threat that is difficult to spot once deployed.
The practical danger is straightforward: a compromised router sits at the edge of a home or office network, so whoever controls it may be able to reach other connected systems behind it. Baines said the implant does not need the router to be exposed to the public internet, because the device itself makes the outbound connection. In testing, VulnCheck researchers were able to intercept that connection and issue a command that produced an interactive shell.
Baines described the hidden software as a small utility called Remote Control Linux, or rctl, which listens for commands on port 7000 and can also open a second channel on port 7001 for an interactive shell. He said there is no meaningful authentication step, no negotiation and no safeguard around what the server sends. Once the router reaches out, the response is passed to the operating system and run as root.
VulnCheck said it did not treat the finding as a normal patchable flaw, because the backdoor appears to have been placed there deliberately. The firm recommended that organisations identify any affected models, look for Zbtlink, ZBT, ZBTWiFi and Wiflyer devices, and treat unbranded cellular CPE of uncertain origin with particular caution. Its advice is to replace the hardware where possible, or at minimum place it behind strict egress controls and monitor for outbound traffic on ports 7000 and 7001.
The warning fits a broader pattern that has long worried governments and security teams about hidden functions in networking gear. Tom’s Hardware recently reported a separate backdoor in Tenda routers that remained unpatched after disclosure, while earlier reporting has highlighted similar concerns in Netcore and Zyxel devices. Together, those cases underline a simple lesson for consumers and businesses alike: with routers, trust in the hardware can matter as much as the software running on it.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





