Chinese-made Zbtlink routers have been found to ship with a backdoor that opens unauthenticated root shells, posing a significant security risk to users. This issue has been uncovered by cybersecurity researchers at VulnCheck, who have detailed the implications of this discovery in a recent report. The backdoor, codenamed ENDLESSDOORS, is a small tool called rctl, uploaded to GitHub in 2015 and never updated since. It acts as a command and control client and server, allowing attackers to remotely control the router and gain a live interactive root shell. The vulnerability lies in the lack of authentication and the ability to hijack the client/server communication, enabling unauthorized access to the router's core functions.
What makes this particularly concerning is the widespread presence of the backdoor in various Zbtlink router models. According to the report, 21 firmware images spanning over two years contain the implant, which starts automatically at boot and attempts to connect to Chinese command-and-control infrastructure every 35 seconds. The affected models include CPE2801, WE1026-5G-WD, WE1326, and many others, all of which dial the same set of primary and secondary endpoints. The presence of the backdoor in these routers highlights the importance of thorough security audits and the need for manufacturers to prioritize user data protection.
The impact of this discovery extends beyond individual users. As the report notes, anyone along the network path can potentially hijack the client/server communication, giving them control over the router. This raises concerns about the security of network infrastructure and the potential for widespread attacks. The fact that the backdoor has been present in the firmware for an extended period without detection further emphasizes the need for robust security measures and regular firmware updates.
In response to the discovery, Zbtlink has temporarily taken down the impacted firmware versions from download channels and is working on developing and validating secured patched firmware. Users are advised to take proactive steps to protect their routers, such as checking the process list, scanning the file system for suspicious files, and blocking egress points. This incident serves as a stark reminder of the ongoing challenges in maintaining a secure digital environment and the importance of staying vigilant against emerging threats.