Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
VulnCheck disclosed ENDLESSDOORS, a factory-shipped backdoor embedded in at least 20 Zbtlink router models and present across all 21 available firmware images. The implant runs at boot, phones home to multiple command-and-control endpoints, and can be hijacked to grant attackers a live root shell on affected devices. #ENDLESSDOORS #Zbtlink #rctl

Keypoints

  • ENDLESSDOORS is a factory-shipped backdoor found in Zbtlink router firmware.
  • The implant starts automatically and beacons to external C2 servers every 35 seconds.
  • It disguises itself as a Linux kworker process while running with root privileges.
  • Researchers traced the backdoor to an old GitHub tool called rctl.
  • Affected users should check for skworker-related files and block the listed endpoints.

Read More: https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html