Zbtlink routers harbor factory-installed ENDLESSDOORS backdoor
Security firm VulnCheck discovered that at least 20 models of routers manufactured by Shenzhen‑based Zbtlink Electronics contain a hidden implant named ENDLESSDOORS. The flaw is catalogued as CVE‑2026‑66747 and gives unauthenticated root‑shell access, allowing an attacker to control the device and any other equipment on the same network. The implant automatically contacts a China‑registered domain every 35 seconds, sending a short registration message that includes the router’s MAC address; the server can then issue arbitrary commands or open an interactive shell.
Zbtlink has suspended sales of the affected models, removed the compromised firmware from its website and said it is developing patches. The company claims the code was intended only as an after‑sales technical‑support tool, but researchers say it was deliberately hidden. Analysts estimate that at least 100,000 routers with the backdoor are deployed worldwide, exposing homes and small‑business networks to potential takeover.
The vulnerability has drawn renewed attention from Western regulators. The Canadian government issued a security advisory, and the U.S. FCC has previously restricted imports of Chinese consumer routers for national‑security reasons. Experts warn that the only reliable mitigation is to disconnect the devices from networks until a clean firmware update is available.
Entities: Canadian government · Endlessdoors · Federal Communications Commission · Forescout · Forescout Research – Vedere Labs · Jacob Baines · Omada · TP-Link · TP‑Link · Zbtlink Electronics · Zbtlink Electronics (Shenzhen Zhibotong Electronics)
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 13 SOURCES] The backdoor contacts a China‑registered domain every 35 seconds. (belongs)
- [● 3 SOURCES] The U.S. FCC has restricted imports of Chinese consumer routers for national‑security reasons. (U.S. regulator actions)
- [● 9 SOURCES] More than 20 models of Zbtlink routers contain a hidden backdoor named ENDLESSDOORS. (VulnCheck research)
- [● 6 SOURCES] The backdoor was discovered by VulnCheck researcher Jacob Baines. (VulnCheck)
- [● 11 SOURCES] The vulnerability is catalogued as CVE‑2026‑66747. (belongs)
- [● 12 SOURCES] At least 100,000 routers with the backdoor are deployed worldwide. (belongs)
- [● 12 SOURCES] The ENDLESSDOORS backdoor provides unauthenticated root‑shell access to the router. (belongs)
- [● 12 SOURCES] Zbtlink removed the affected firmware from its website and announced an emergency product pull. (belongs)
- [● 13 SOURCES] At least 20 Zbtlink router models contain a pre‑installed remote‑access implant called ENDLESSDOORS (CVE‑2026‑66747). (belongs)
- [● 2 SOURCES] The Canadian government issued a security advisory about the Zbtlink router vulnerability. (belongs)
- [● 3 SOURCES] Jacob Baines of cybersecurity firm VulnCheck discovered the Zbtlink backdoor. (ea9f8e7c-a586-486a-8c33-db3d36d10416, a4046929-26fd-4a1e-bac2-ae7b6da94d31, 0c4e97c8-df70-4e13-8d07-2b41ef594517)
- [● 12 SOURCES] Zbtlink Electronics suspended sales of the affected routers and removed the firmware while developing patches. (belongs)