Factory-installed backdoor in Zbtlink and Wiflyer routers exposes over 100,000 homes to attack

Security researchers have uncovered a severe factory-installed backdoor, dubbed ENDLESSDOORS, in certain Zbtlink and Wiflyer routers, risking the safety of more than 100,000 households before users could change default passwords, highlighting the growing threat to smart home networks.

Security researchers say a router backdoor discovered in several Zbtlink and Wiflyer models may have left more than 100,000 households exposed before customers even had a chance to change a password. Forkast reported that the flaw, tracked as CVE-2026-66747 and dubbed ENDLESSDOORS, appears to have been factory-installed rather than added by an intruder after the fact. That distinction matters: if accurate, it means the device was compromised at the point of manufacture, not after purchase.

According to Forkast, the implant runs with root privileges, launches at boot through an init script and repeatedly contacts hard-coded command-and-control servers in clear text. The report said an operator can obtain an interactive root shell by using a reserved string, while Zbtlink has described the component as an “after-sales technical support tool”. The company has since halted sales and said it is working on a firmware update, but the reporting suggests the design flaw is severe enough to carry a CVSS score of 9.3.

The case fits a broader pattern of router insecurity that security researchers have been warning about for years. TechRadar and BleepingComputer recently reported that multiple Tenda models contain an unpatched backdoor, CVE-2026-11405, which can let an attacker reach the administrative interface without valid credentials. Those reports said CERT/CC disclosed the issue and Tenda had not yet released a fix, leaving users to rely on workarounds such as disabling remote web management and reducing exposure on local networks.

Other manufacturers have also had to respond to serious flaws. Malwarebytes reported that TP-Link warned customers about a botnet campaign exploiting vulnerabilities in older SOHO routers, including the Archer C7 and TL-WR841N/ND, to attack Microsoft 365 accounts. TP-Link has since issued firmware updates for the affected devices, including some that have reached end of life, while also publishing a separate advisory for a command-injection flaw that could allow unauthorised remote control if exploited during device setup.

For consumers, the uncomfortable lesson is that the home router is no longer just a piece of networking kit. It is the gatekeeper for cameras, locks, speakers and every other connected device behind it. If the gateway itself is untrustworthy, the rest of the smart home inherits that risk. ENDLESSDOORS, if the reporting holds, shows how a supply chain failure can turn the most basic device in the house into the most dangerous one.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.