Chinese router maker's firmware backdoors prompt urgent security warnings

Research reveals that Zbtlink routers contain a built-in backdoor allowing root access, prompting calls for device replacement and stricter network controls amid growing router security concerns.

A Chinese networking company has been accused of shipping routers with a built-in backdoor that could let an attacker issue commands as root and open a reverse shell, according to research published by VulnCheck. Jacob Baines, the company’s chief technology officer, said the behaviour was present in Zbtlink firmware and that affected devices repeatedly tried to contact an internet-facing command-and-control server.

Baines labelled the mechanism ENDLESSDOORS and said it had been uploaded to GitHub in 2015, then left unchanged. In his analysis, the protocol effectively allowed two high-privilege actions: running commands as root and spawning a root shell. He also said the communication could be intercepted and hijacked in transit, raising the risk that an attacker on the network path could take control.

Zbtlink rejected the suggestion of malicious intent, telling The Register that the code was meant only for after-sales maintenance and debugging on sample units, not for mass-produced hardware. The company nevertheless appears to have moved to contain the issue, with a warning posted on its downloads page saying selected firmware releases had been temporarily removed while engineers worked on patched versions.

The situation comes against a broader backdrop of router security problems. Zbtlink has separately published advisories about other firmware and cloud weaknesses, and other vendors have also faced serious device security failures, including authentication bypasses and persistent backdoors that survive firmware updates. In this case, VulnCheck’s advice was blunt: for devices carrying real traffic, replacement is the safest option, or at minimum strict egress controls should be enforced and the local network treated as untrusted.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.