Ethical Hacking News
The discovery of a factory-shipped backdoor in at least 20 Chinese-made router models from Zbtlink has raised significant concerns among cybersecurity experts and users worldwide. The vulnerability, codenamed "ENDLESSDOORS," allows attackers to gain control over routers without having to be reachable from the internet.
At least 20 different models of Chinese-made Zbtlink routers have been found to contain a factory-shipped backdoor. The vulnerability, codenamed "ENDLESSDOORS," allows attackers to gain control over the router without authentication. The affected models include various CPE and WE series numbers, with some being temporarily removed from download channels. Users are advised to block egress points, check process lists, and scan file systems for suspicious files until fixed firmware is available. The discovery highlights the importance of regularly updating firmware and taking proactive measures to secure devices against emerging threats.
The world of cybersecurity is constantly plagued by new and innovative attacks, each one designed to exploit a specific vulnerability in our devices and systems. In recent times, researchers have discovered a grave threat lurking within the firmware of certain Chinese-made routers, which poses significant risks to users worldwide.
According to a recent report from VulnCheck, at least 20 different models of Zbtlink routers have been found to contain a factory-shipped backdoor that opens unauthenticated root shells. This vulnerability, codenamed "ENDLESSDOORS," was discovered by cybersecurity researchers who analyzed the firmware images currently available on the manufacturer's website.
The "ENDLESSDOORS" backdoor is designed such that it starts automatically and attempts to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds. It masquerades as a Linux kernel thread but is actually a userland process running with root privileges, blending its true functionality with other legitimate kworker processes.
Experts have expressed concern over the fact that there is no handshake, negotiation, or authentication involved in this vulnerability. Once the implant sends a "hello" message to the server alongside the LAN MAC address, it's engineered to run whatever the server sends back in response. This makes it possible for an attacker to take advantage of this loophole and hijack the outbound rctl communications, thereby obtaining a live root shell and gaining control over the router without having to be reachable from the internet.
The affected models include CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and Z8102AX-2DSIM.
Researchers have noted that every firmware listed on zbtlink.com's download page embeds the rctl implant and starts it at boot with an init.d script named "skworker." The list of affected models has been found to dial the same set of four primary and secondary endpoints: zbtctl.epplink.net (47.100.190[.]96), 47.107.224[.]89, online-string[.]com (45.32.81[.]152), and rbdg4nzqadui.wikaba[.]com (43.248.136[.]125).
In response to this vulnerability, the Chinese router manufacturer has temporarily taken down the impacted firmware versions from download channels and is working intensely to develop and validate secured patched firmware.
As users visit the firmware downloads page on Zbtlink's website, they are displayed a message warning of firmware security vulnerabilities affecting selected router firmware releases. The company has assured its customers that it will notify them immediately once the fixed, security-validated firmware is available for release.
In the meantime, users are advised to check the process list and scan the file system for files like /usr/sbin/kworker, /usr/lib/librctl.so, /etc/kworker.cfg, and /etc/init.d/skworker. They should also block the egress points to prevent any potential attacks.
The discovery of this vulnerability highlights the importance of regularly updating firmware and taking proactive measures to secure our devices against such threats. It serves as a wake-up call for cybersecurity professionals and users alike, emphasizing the need for vigilance in the face of emerging threats.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Hidden-Threat-Lurking-Within-Chinese-Made-Routers-A-Grave-Vulnerability-Exposed-ehn.shtml
https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
Published: Thu Aug 6 03:53:45 2026 by llama3.2 3B Q4_K_M