Ethical Hacking News
A Chinese router vendor has been accused of including a backdoor feature in its firmware, sparking concerns about the security and integrity of connected devices. Despite initial denials, Zbtlink has since paused downloads of its firmware and announced plans to develop secured patched versions. The incident highlights the need for greater transparency and cooperation between vendors, researchers, and regulators in the face of emerging threats.
Zbtlink's firmware allegedly contains a backdoor feature called "ENDLESSDOORS" that allows remote maintenance.The backdoor is believed to be activated by an init script shipped with the router firmware and continuously attempts to reach a command and control server on the internet.Over 20 different Zbtlink router models contain this alleged backdoor, raising concerns about supply chain attacks.Zbtlink has paused downloads of its firmware and plans to develop and validate secured patched firmware.The company's explanation for the feature is increasingly dubious in light of new evidence, leading some to question their initial denial of wrongdoing.
Chinese router vendor Zbtlink has been embroiled in a controversy surrounding allegations of a backdoor feature in its firmware, sparking concerns about the security and integrity of connected devices. According to VulnCheck, a provider of threat intelligence platforms, the alleged backdoor is codenamed "ENDLESSDOORS" and is believed to be a remote maintenance function that allows the device to phone home to a command and control server on the internet.
The backdoor, which is allegedly implemented in the Linux kernel, is said to be activated by an init script shipped with the router firmware. This script, according to VulnCheck chief technology officer Jacob Baines, continuously attempts to reach a command and control server on the internet. The alleged backdoor has been identified as a potential security vulnerability that could allow hackers to remotely access the device.
Despite Zbtlink's initial denial of any wrongdoing, it has since paused downloads of its firmware and announced plans to develop and validate secured patched firmware. The company claims that the feature is solely intended for after-sales maintenance and serves no other purposes, but this explanation appears increasingly dubious in light of new evidence.
A review of Zbtlink's download page reveals a cryptic update on router firmware security remediation, which states that selected firmware releases have been affected by security vulnerabilities. As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. This admission appears to contradict Zbtlink's earlier claims of no security problems.
Furthermore, VulnCheck has discovered that numerous Zbtlink router models contain this alleged backdoor, with over 20 different devices affected by the security vulnerability. The fact that these devices are designed to operate independently and can be customized by customers raises concerns about the potential for supply chain attacks.
Baines' post includes rules to block access to the endpoints the routers contact, as well as advice on how to detect possibly infected machines. He also advises users to replace their device or move it behind strict egress control and treat its LAN as untrusted. These recommendations suggest that users are taking extreme precautions to mitigate the potential risks posed by the alleged backdoor.
The incident has sparked a heated debate about the responsibility of companies in the tech industry to disclose security vulnerabilities and cooperate with researchers and law enforcement agencies. VulnCheck's decision not to follow traditional coordinated disclosure procedures due to concerns about the severity of the issue highlights the need for greater transparency and collaboration between vendors, researchers, and regulators.
As the investigation into this alleged backdoor scandal continues, it remains to be seen whether Zbtlink will be able to restore the trust of its customers and the wider industry. One thing is certain, however: the case serves as a stark reminder of the importance of robust security measures and the need for continued vigilance in the face of emerging threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Exposing-a-Web-of-Deceit-The-Alleged-Backdoor-Scandal-Rocking-the-Networking-Industry-ehn.shtml
https://www.theregister.com/security/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/5283794
https://www.cnet.com/home/internet/hidden-backdoor-found-in-chinese-made-zbtlink-routers/
Published: Thu Aug 6 00:26:13 2026 by llama3.2 3B Q4_K_M