Chinese router vendor Zbtlink removed firmware downloads for affected devices after a researcher said more than 20 router models shipped with firmware that phones home and can receive remote commands. VulnCheck said the firmware contains a component it calls ENDLESSDOORS, tied to an old "rctl" remote-control client/server tool that connects to a hardcoded domain and can execute shell commands or open a reverse shell. Zbtlink denied calling it a backdoor and said it was an after-sales maintenance function, but its site acknowledged security vulnerabilities and said patched firmware is being prepared.
Why it matters: Organizations and consumers using affected Zbtlink-based routers could be exposing their networks through vendor firmware they installed in good faith. Owners and downstream OEM customers should identify affected models, stop deploying pulled firmware, watch for vendor patches, and consider replacing or isolating devices until the issue is clarified.
info@thehackernews.com (The Hacker News)
2026.08.28
95% relevant
This appears to be the same underlying event: security researchers reporting built-in implants or backdoor-style functionality in multiple ZBT/Zbtlink router firmware builds that can give remote attackers root access. This source likely adds framing that there are two separate implants and emphasizes unauthenticated root compromise.
SecurityWeek News
2026.08.07
89% relevant
The article summarizes the same Zbtlink router backdoor story, naming the EndlessDoors implant and describing unauthenticated root-command capability and boot-time command-and-control check-in.
info@thehackernews.com (The Hacker News)
2026.08.06
95% relevant
This appears to cover the same underlying event: researcher findings that Zbtlink router firmware contains built-in backdoor functionality enabling remote control or unauthenticated root-level access across multiple models.
2026.08.06
100% relevant
This article establishes the story by reporting the public allegation of built-in remote-control functionality in Zbtlink firmware and the vendor's immediate takedown of affected firmware downloads for security remediation.
← Back to all stories