# Consumer router security flaws 2026

> Live situation record from CLSTR: https://clstr.news/situations/consumer-router-security-flaws-2026
> Updated: 2026-08-06T02:45:15.000Z. Sources: 9. Developments: 2.

In July 2026 a security flaw was reported in Tenda Wi‑Fi routers sold in Slovakia, marking the first public notice of a vulnerability affecting a Chinese‑made consumer networking device in Europe.

The following month, researchers at VulnCheck disclosed a firmware‑level backdoor—named ENDLESSDOORS and catalogued as CVE‑2026‑66747—in more than 20 Zbtlink router models sold worldwide. The implant granted unauthenticated root‑shell access and periodically contacted a China‑registered domain. Zbtlink withdrew the compromised firmware and announced a recall, while regulators in the United States and Canada imposed import restrictions and issued safety alerts. Together, the incidents highlight growing concerns over supply‑chain security in low‑cost routers and the challenges of mitigating factory‑installed firmware implants.

## Claims

- More than 20 models of Zbtlink routers contain a hidden backdoor named ENDLESSDOORS. (corroborated by 9 sources)
- The ENDLESSDOORS backdoor provides unauthenticated root‑shell access to the router. (corroborated by 6 sources)
- The backdoor was discovered by VulnCheck researcher Jacob Baines. (corroborated by 6 sources)
- The backdoor contacts a China‑registered domain every 35 seconds. (corroborated by 5 sources)
- At least 100,000 routers with the backdoor are deployed worldwide. (corroborated by 4 sources)
- The vulnerability is catalogued as CVE‑2026‑66747. (corroborated by 3 sources)
- The U.S. FCC has restricted imports of Chinese consumer routers for national‑security reasons. (corroborated by 3 sources)
- Zbtlink removed the affected firmware from its website and announced an emergency product pull. (corroborated by 2 sources)

## Timeline

### 2026-08-06: Zbtlink routers found with built‑in backdoor affecting 20+ models worldwide

VulnCheck found a built‑in backdoor (ENDLESSDOORS, CVE‑2026‑66747) in 20+ Zbtlink router models, giving unauthenticated root access and contacting a Chinese server every 35 seconds; at least 100,000 devices may

9 sources. https://clstr.news/cluster/zbtlink-routers-with-endlessdoors-backdoor-affect-up-to-100000-devices-worldwide

### 2026-07-11: Security flaw discovered in Tenda WiFi routers sold in Slovakia

CERT/CC reports a backdoor‑type flaw (CVE‑2026‑11405) in Tenda routers sold in Slovakia, urging users to disable remote management and install updates.

2 sources. https://clstr.news/cluster/security-flaw-discovered-in-tenda-wifi-routers-sold-in-slovakia

---
Cite as: Consumer router security flaws 2026. CLSTR, https://clstr.news/situations/consumer-router-security-flaws-2026
