< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

3 clusters · 21 sources · 23 days · First seen · Last updated

Zbtlink router ENDLESSDOORS and additional implant discovery

Overview

Security researchers at VulnCheck have expanded their findings regarding malicious implants in routers manufactured by Shenzhen-based Zbtlink Electronics (also known as Shenzhen Zhibotong Electronics or ZBT). While the initial discovery focused on the ‘ENDLESSDOORS’ implant, which provides unauthenticated root-shell access via a modified ‘rctl’ tool, subsequent research has identified additional factory-installed implants named ‘SPEAKINGSTONE’ and ‘DARKLANTERN’.

ENDLESSDOORS, catalogued as CVE-2026-66747, allows attackers to control devices and connected network equipment by contacting a China-registered domain every 35 seconds. The hardware is distributed as OEM or ODM products under various brands, including Zbtlink and Wiflyer.

New findings reveal that DARKLANTERN operates via UDP port 9992, allowing arbitrary shell commands due to ineffective firewall settings. SPEAKINGSTONE operates via UDP port 10000, enabling attackers to exfiltrate WAN PPPoE credentials, perform DNS hijacking, and establish reverse SSH tunnels. DARKLANTERN has been identified in 22 countries.

Zbtlink has suspended sales of affected models and removed compromised firmware from its website, claiming the code was intended as an “after-sales technical-support tool.” Analysts estimate at least 100,000 routers are deployed worldwide. Experts warn that the only reliable mitigation is to disconnect devices from networks until clean firmware updates are available.

Entities

Shenzhen Zhibotong Electronics · VulnCheck · Federal Communications Commission · Endlessdoors · TP‑Link

Timeline

  1. 29 days ago

    [TECHNOLOGY] 6 sources
    ZBT routers found with firmware implants providing root access

    Two firmware implants, SPEAKINGSTONE and DARKLANTERN, found in ZBT-manufactured routers allow unauthenticated attackers to gain root access, steal credentials, and hijack DNS settings globally.

  2. about 2 months ago

    [TECHNOLOGY] 2 sources
    Zbtlink routers found with embedded spyware component

    Researchers discovered ‘ENDLESSDOORS’, a malicious component in Zbtlink and Wiflyer routers that allows remote root access via unauthorized outbound connections to external servers.

  3. about 2 months ago

    [TECHNOLOGY] 13 sources
    Zbtlink routers harbor factory-installed ENDLESSDOORS backdoor

    Zbtlink routers (≥20 models, CVE‑2026‑66747) contain a factory‑installed ENDLESSDOORS backdoor that gives root access, contacts a China‑registered domain every 35 seconds, and affects an estimated 100,000 units

Sources

au.pcmag.com · borncity.com · cyberinsider.com · dev.to · finance.technews.tw · flagthis.com · forkast.news · gulf-insider.com · m.winfuture.de · news.hkheadline.com.hk · securityaffairs.co · sf-encyclopedia.com · sketcher.startitup.sk · sofx.com · startitup.sk · techmaniacs.gr · techritual.com · thehackernews.com · uk.pcmag.com · unwire.hk · wtvbam.com

This summary has been updated 1 time: see revision history