Researchers uncover a concealed backdoor embedded in popular Zbtlink routers, exposing over 100,000 units to remote control and highlighting deepening trust concerns in low-cost networking gear.
Cybersecurity researchers say they have uncovered a hidden control component inside a family of consumer routers sold under the Zbtlink name and rebranded by others, including Wiflyer, raising fresh concerns about supply-chain trust in low-cost networking gear. VulnCheck said the implanted software, which it has labelled ENDLESSDOORS and tracked as CVE-2026-66747, is present in firmware shipped on devices sold through major marketplaces and appears to be built into the product rather than added later by an intruder. The finding comes as consumers and businesses continue to face a steady stream of router flaws that can expose home and small-office networks to remote compromise.
According to VulnCheck’s analysis, the component wakes up at boot, disguises itself as a normal Linux system process and begins contacting servers in China every 35 seconds. The researchers said the traffic is outbound, which means it can pass through NAT devices and firewalls like ordinary web or cloud traffic. Once connected, the remote operator can issue shell commands as root or open an interactive shell on ports 7000 and 7001, giving full control of the device. VulnCheck said the communication is unencrypted and unauthenticated, leaving no meaningful barrier for interception or misuse.
The scale is significant. VulnCheck estimated that more than 100,000 units are affected across more than 20 models, including CPE2801, WE1026-5G-WD, WE2007, WG108 and WG3526, along with white-label variants. The company said the routers were manufactured by Shenzhen Zhibotong Electronics and distributed under several badges through online retailers. That broader pattern echoes other recent router security cases, including separate reports on unpatched Tenda backdoors that, according to Tom’s Hardware, TechRadar, BleepingComputer and others, could grant administrative access without a password.
Zbtlink has rejected the suggestion that the code amounts to an intentional backdoor, saying it is meant for after-sales support and was intended for debugging sample units rather than mass-market devices. But VulnCheck said the vendor’s own download page then began displaying a notice acknowledging firmware security issues on selected versions and temporarily removing affected files, which the researchers said did not appear before publication. With no fixed firmware available, VulnCheck advised owners to disconnect and replace affected routers rather than rely on a factory reset or password change, arguing that the problem lies in the device’s firmware trust model itself.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





