Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
3 clusters · 21 sources · 23 days · First seen · Last updated
Zbtlink router ENDLESSDOORS and additional implant discovery
Overview
Security researchers at VulnCheck have expanded their findings regarding malicious implants in routers manufactured by Shenzhen-based Zbtlink Electronics (also known as Shenzhen Zhibotong Electronics or ZBT). While the initial discovery focused on the ‘ENDLESSDOORS’ implant, which provides unauthenticated root-shell access via a modified ‘rctl’ tool, subsequent research has identified additional factory-installed implants named ‘SPEAKINGSTONE’ and ‘DARKLANTERN’.
ENDLESSDOORS, catalogued as CVE-2026-66747, allows attackers to control devices and connected network equipment by contacting a China-registered domain every 35 seconds. The hardware is distributed as OEM or ODM products under various brands, including Zbtlink and Wiflyer.
New findings reveal that DARKLANTERN operates via UDP port 9992, allowing arbitrary shell commands due to ineffective firewall settings. SPEAKINGSTONE operates via UDP port 10000, enabling attackers to exfiltrate WAN PPPoE credentials, perform DNS hijacking, and establish reverse SSH tunnels. DARKLANTERN has been identified in 22 countries.
Zbtlink has suspended sales of affected models and removed compromised firmware from its website, claiming the code was intended as an “after-sales technical-support tool.” Analysts estimate at least 100,000 routers are deployed worldwide. Experts warn that the only reliable mitigation is to disconnect devices from networks until clean firmware updates are available.
Entities
Shenzhen Zhibotong Electronics · VulnCheck · Federal Communications Commission · Endlessdoors · TP‑Link
Timeline
-
29 days ago
[TECHNOLOGY] 6 sourcesZBT routers found with firmware implants providing root accessTwo firmware implants, SPEAKINGSTONE and DARKLANTERN, found in ZBT-manufactured routers allow unauthenticated attackers to gain root access, steal credentials, and hijack DNS settings globally.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesZbtlink routers found with embedded spyware componentResearchers discovered ‘ENDLESSDOORS’, a malicious component in Zbtlink and Wiflyer routers that allows remote root access via unauthorized outbound connections to external servers.
-
about 2 months ago
[TECHNOLOGY] 13 sourcesZbtlink routers harbor factory-installed ENDLESSDOORS backdoorZbtlink routers (≥20 models, CVE‑2026‑66747) contain a factory‑installed ENDLESSDOORS backdoor that gives root access, contacts a China‑registered domain every 35 seconds, and affects an estimated 100,000 units
Sources
au.pcmag.com · borncity.com · cyberinsider.com · dev.to · finance.technews.tw · flagthis.com · forkast.news · gulf-insider.com · m.winfuture.de · news.hkheadline.com.hk · securityaffairs.co · sf-encyclopedia.com · sketcher.startitup.sk · sofx.com · startitup.sk · techmaniacs.gr · techritual.com · thehackernews.com · uk.pcmag.com · unwire.hk · wtvbam.com
This summary has been updated 1 time: see revision history