A cybersecurity firm has identified a covert remote-control feature in multiple models of Zbtlink routers, prompting questions over security practices amid a wider scrutiny of Chinese networking hardware.
A cybersecurity firm says it has uncovered a hidden remote-access function in 20 Wi-Fi router models sold by Chinese vendor Zbtlink, raising fresh questions about the security of low-cost networking hardware. The company, VulnCheck, said the issue was found in firmware for a Zbtlink AX3000 router it bought through Alibaba, after noticing code that appeared to call home to an obscure internet address and could accept remote commands. Zbtlink has pushed back, saying the component is only an “after-sales technical support tool” intended for customer troubleshooting and configuration when explicitly authorised. According to Zbtlink’s own security notices, the company has also issued firmware fixes for other vulnerabilities in its products and urges users to update quickly.
VulnCheck said the code closely resembles a remote-control Linux tool known as rctl, first posted on GitHub years ago, and warned that the implant is present across roughly two dozen firmware images on Zbtlink’s website. The researchers said the same mechanism appears in multiple models and can be activated at boot through an init script, making affected devices vulnerable to hidden control by whoever manages the server they contact. Zbtlink sells some routers under third-party brand names as well, so VulnCheck advised customers to check model numbers rather than labels on the casing. The firm told Reuters it believes at least 100,000 affected routers are deployed worldwide.
Zbtlink said sales of the affected models have been suspended and the relevant firmware downloads removed while it develops updates to address the problem. The company said it is working on new firmware to fully resolve the issue and added that the component had never been used for unauthorised access. In a separate security bulletin, ZBT said it has been releasing patches for vulnerabilities in its router and cloud products and recommends upgrading to firmware version 3.215 or later for one identified command-injection flaw.
The episode comes amid wider scrutiny of Chinese-made routers and other networking gear. Researchers recently flagged another undocumented backdoor in Tenda routers, while TP-Link has warned about botnets exploiting vulnerabilities in older models and other security firms have reported persistent router infections that survive routine updates. In the United States, the Trump administration has barred new foreign-made Wi-Fi router models from being sold on national security grounds, and no Chinese vendor has yet received an FCC waiver.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





