VulnCheck Says Some Zbtlink Routers Ship With Factory-Installed Remote Access Software
A router is supposed to connect your devices to the internet not quietly connect itself to someone else. Security researchers at VulnCheck disclosed on Aug. 5 that at least 20 consumer and small-business router models made by Chinese manufacturer Zbtlink ship with a factory-installed remote-access backdoor.
Researchers estimate more than 100,000 devices have been sold worldwide, many through Amazon and other mainstream retailers.
The catch is that many owners may never have heard of Zbtlink. The company manufactures networking hardware for other brands, meaning the logo on the router may not match the company that actually built its firmware.
Unlike malware installed after purchase, the software researchers discovered is already present when the router leaves the factory. VulnCheck named the implant ENDLESSDOORS.
“The routers phone home, waiting for orders not because they were hacked, but because they were shipped that way,” Jacob Baines, Chief Technology Officer at VulnCheck, wrote when the company disclosed the ENDLESSDOORS implant on Aug. 5.
“If you deployed one of these in a university or enterprise environment, it could provide an attacker with a foothold into the broader network,” Jacob Baines told Reuters, describing the potential impact beyond a single consumer device.
Researchers found the implant could receive commands with full administrative privileges, effectively allowing whoever controls the communication channel to take over the router.
Why researchers call it a backdoor
According to VulnCheck, the software establishes a persistent outbound connection without authentication or cryptographic verification. Rather than confirming it’s talking to an authorized management server, it simply registers itself and waits for instructions.
That design means the communication channel could potentially be hijacked by anyone capable of controlling the destination server or intercepting the network traffic, making it far riskier than a conventional remote-support tool.
The white-label problem
“Consumers often don’t realize they’re buying the same underlying hardware under different brand names,” Jacob Baines told CNET, explaining why firmware issues in one OEM can affect numerous retail products.
As a result, consumers may buy what appears to be a product from a European or American brand when the underlying hardware and firmware come from the same manufacturer.
VulnCheck says the confirmed list currently includes 20 models, but because Zbtlink also produces hardware for third-party brands, additional rebranded devices could be affected.
The finding also fits a broader pattern. Researchers have previously uncovered hidden remote-access functionality in low-cost router brands including Jetstream and Wavlink, with some later exploited in real-world attacks.
What owners should do
Zbtlink disputes the “backdoor” characterization, describing the component as an after-sales technical support tool and saying security updates are being developed. Researchers argue that legitimate support mechanisms should require authentication and explicit user approval.
“This is an after-sales technical support component rather than a malicious backdoor, and updated firmware is being prepared,” Zbtlink said in its response after VulnCheck published its findings.
If you own a low-cost router from an unfamiliar manufacturer, first identify who actually built the hardware rather than relying solely on the retail brand. If your model appears on VulnCheck’s affected list, disable remote management if it’s not needed, change default administrator credentials and consider replacing the device especially if it connects work computers, financial accounts or security cameras.