Zbtlink routers found with built‑in backdoor affecting 20+ models worldwide
Security researchers at VulnCheck have identified a firmware‑level backdoor, dubbed ENDLESSDOORS and tracked as CVE‑2026‑66747, embedded in more than 20 models of routers manufactured by Shenzhen Zhibotong Electronics (Zbtlink). The implant provides unauthenticated root‑shell access and automatically contacts a China‑registered domain every 35 seconds, allowing an attacker to execute commands or open an interactive shell on the device.
The vulnerable routers, sold under the Zbtlink and Wiflyer brands on platforms such as Amazon, AliExpress and Alibaba, are estimated to number at least 100,000 units worldwide. Zbtlink responded by pulling the affected firmware from its website and announcing an emergency product recall, claiming the feature was intended only for remote technical support. Western governments, including the U.S. Federal Communications Commission, have already imposed restrictions on imports of Chinese‑made consumer routers because of similar security concerns, and Canada issued a safety alert following the disclosure.
The discovery adds to ongoing worries about supply‑chain risks in low‑cost networking hardware and highlights the difficulty of defending against implants that operate at the factory‑installed firmware level.
Entities: Endlessdoors · Federal Communications Commission (FCC) · Jacob Baines · Shenzhen Zhibotong Electronics · Shenzhen Zhibotong Electronics (Zbtlink) · VulnCheck · Zbtlink
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 5 SOURCES] The backdoor contacts a China‑registered domain every 35 seconds. (VulnCheck report)
- [● 3 SOURCES] The U.S. FCC has restricted imports of Chinese consumer routers for national‑security reasons. (U.S. regulator actions)
- [● 9 SOURCES] More than 20 models of Zbtlink routers contain a hidden backdoor named ENDLESSDOORS. (VulnCheck research)
- [● 6 SOURCES] The backdoor was discovered by VulnCheck researcher Jacob Baines. (VulnCheck)
- [● 3 SOURCES] The vulnerability is catalogued as CVE‑2026‑66747. (CVE database)
- [● 4 SOURCES] At least 100,000 routers with the backdoor are deployed worldwide. (VulnCheck estimate)
- [● 6 SOURCES] The ENDLESSDOORS backdoor provides unauthenticated root‑shell access to the router. (VulnCheck analysis)
- [● 2 SOURCES] Zbtlink removed the affected firmware from its website and announced an emergency product pull. (Zbtlink statement)