Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 9 sources · 27 days · First seen · Last updated
Categories: TECHNOLOGY
Consumer router security flaws 2026
Entities: Endlessdoors · Shenzhen Zhibotong Electronics · Jacob Baines · VulnCheck · Shenzhen Zhibotong Electronics (Zbtlink)
Overview
In July 2026 a security flaw was reported in Tenda Wi‑Fi routers sold in Slovakia, marking the first public notice of a vulnerability affecting a Chinese‑made consumer networking device in Europe.
The following month, researchers at VulnCheck disclosed a firmware‑level backdoor—named ENDLESSDOORS and catalogued as CVE‑2026‑66747—in more than 20 Zbtlink router models sold worldwide. The implant granted unauthenticated root‑shell access and periodically contacted a China‑registered domain. Zbtlink withdrew the compromised firmware and announced a recall, while regulators in the United States and Canada imposed import restrictions and issued safety alerts. Together, the incidents highlight growing concerns over supply‑chain security in low‑cost routers and the challenges of mitigating factory‑installed firmware implants.
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 9 SOURCES] More than 20 models of Zbtlink routers contain a hidden backdoor named ENDLESSDOORS. (VulnCheck research)
- [● 6 SOURCES] The ENDLESSDOORS backdoor provides unauthenticated root‑shell access to the router. (VulnCheck analysis)
- [● 6 SOURCES] The backdoor was discovered by VulnCheck researcher Jacob Baines. (VulnCheck)
- [● 5 SOURCES] The backdoor contacts a China‑registered domain every 35 seconds. (VulnCheck report)
- [● 4 SOURCES] At least 100,000 routers with the backdoor are deployed worldwide. (VulnCheck estimate)
- [● 3 SOURCES] The vulnerability is catalogued as CVE‑2026‑66747. (CVE database)
- [● 3 SOURCES] The U.S. FCC has restricted imports of Chinese consumer routers for national‑security reasons. (U.S. regulator actions)
- [● 2 SOURCES] Zbtlink removed the affected firmware from its website and announced an emergency product pull. (Zbtlink statement)
Timeline
-
2 days ago
[TECHNOLOGY] 9 sourcesZbtlink routers found with built‑in backdoor affecting 20+ models worldwideVulnCheck found a built‑in backdoor (ENDLESSDOORS, CVE‑2026‑66747) in 20+ Zbtlink router models, giving unauthenticated root access and contacting a Chinese server every 35 seconds; at least 100,000 devices may
-
28 days ago
[TECHNOLOGY] 2 sourcesSecurity flaw discovered in Tenda WiFi routers sold in SlovakiaCERT/CC reports a backdoor‑type flaw (CVE‑2026‑11405) in Tenda routers sold in Slovakia, urging users to disable remote management and install updates.
Sources
finance.technews.tw · flagthis.com · gulf-insider.com · news.hkheadline.com.hk · securityaffairs.co · sf-encyclopedia.com · sofx.com · techritual.com · unwire.hk