Zbtlink Routers' Firmware Backdoor Raises Serious Security Concerns

Zbtlink routers contain a firmware backdoor allowing remote root access, leading to security risks. Users should consider replacing devices or applying strict network controls until patched firmware is available.

Zbtlink Routers' Firmware Backdoor Raises Serious Security Concerns
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What is the security risk posed by Zbtlink routers?

Zbtlink routers have been found to contain a hidden backdoor in their firmware called ENDLESSDOORS, enabling remote attackers to execute root-level commands or open reverse shells. This backdoor allows unauthorized access to the device, bypassing typical security measures, which could lead to compromise of the whole network the router serves.

How does this backdoor operate and why is it dangerous?

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated  Root Shells
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

The backdoor constantly attempts communication with a remote command-and-control server, awaiting instructions. It can run arbitrary commands as root-level user or launch a reverse shell session, effectively giving attackers full control over the device. Furthermore, because the communication protocol used in the backdoor is simple and unencrypted, any attacker can hijack these communications and take control, making the vulnerability easy to exploit.

What has Zbtlink done in response, and what should users do?

Zbtlink denies that the backdoor is malicious, stating it is for after-sales maintenance and normally restricted to sample units. Nonetheless, the company has temporarily removed over 20 firmware versions from their download platforms to fix these security issues. Since all publicly available firmware images appear vulnerable to this backdoor, replacing the device is the most secure option. Alternatively, users should implement strict outbound network controls to block unauthorized communications from the router and treat the local area network as untrusted. These steps reduce exposure to potential hijacking until fixed firmware is deployed.

What are the practical takeaways for network users?

ENDLESSDOORS Zbtlink Router Backdoor: 20 Models
ENDLESSDOORS Zbtlink Router Backdoor: 20 Models

The presence of an undocumented backdoor in routers indicates a high-risk security flaw with real-world consequences. Network administrators and users relying on Zbtlink devices should consider immediate action: replacing affected hardware with trusted models, segmenting router networks, and enforcing stringent egress filtering to limit potential exploitation. Waiting passively for patches without mitigating risks leaves networks vulnerable to remote compromise by attackers exploiting inherent backdoor access.

React to this story

Related Posts