TechNewsReel
Live

Zbtlink Routers Shipped With Root Backdoor Across Multiple Brands

Researchers uncover 'ENDLESSDOORS' root implant in over 20 router models, allowing remote command execution.

TechNewsReel Newsroom · August 6, 2026

Cybersecurity firm VulnCheck has discovered a root backdoor, dubbed 'ENDLESSDOORS,' embedded in the firmware of more than 20 Zbtlink router models. The implant allows for remote shell command execution, granting unauthorized parties full administrative control over the hardware.

The backdoor relies on a tool called 'rctl' (remote control linux), which researchers traced back to a GitHub upload from January 14, 2015. According to VulnCheck, the implant is designed to contact command-and-control (C2) servers as often as every 35 seconds to check for incoming instructions. The vulnerability was identified across a broad range of devices sold under the Zbtlink, ZBT, ZBTWiFi, and Wiflyer brands.

The OEM Connection

Zbtlink operates primarily as an OEM and ODM provider, specializing in customization services. The company frequently promotes the use of OpenWrt, a flexible Linux-based operating system, to allow its clients to develop custom firmware. This architectural openness likely facilitated the widespread integration of the 'rctl' tool across various product lines and firmware versions over several years.

Industry Implications

Because the backdoor operates with root privileges, it creates a critical security failure. An attacker who successfully hijacks the communication channel can gain total control of the router, which can then be used as a pivot point to attack other devices on the local network.

The vendor's response has drawn scrutiny for its contradictions. While a Zbtlink spokesperson stated that the feature was "solely intended for after-sales maintenance and serves no other purposes," the company simultaneously paused firmware downloads on its official website to address "security vulnerabilities." Jacob Baines, CTO of VulnCheck, noted that these routers "phone home, waiting for orders" not because of a third-party hack, but because they were shipped in that state.

Next Steps for Users

Zbtlink has not yet released a comprehensive patch or a detailed list of affected serial numbers, though the suspension of firmware downloads suggests a remediation process is underway. Users of Zbtlink, ZBT, ZBTWiFi, and Wiflyer hardware are advised to monitor official channels for security updates. Until a verified fix is deployed, the persistence of the 'rctl' tool remains a primary concern for network administrators and home users alike.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.