< Back to situation

[REVISION HISTORY]

Zbtlink router ENDLESSDOORS and additional implant discovery

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-10 19:05 UTC → 2026-08-28 13:09 UTC · added removed

Zbtlink router ENDLESSDOORS backdoor and additional implant discovery

Security researchers at VulnCheck identified a have expanded their findings regarding malicious implant named ‘ENDLESSDOORS’ embedded implants in router models routers manufactured by Shenzhen-based Zbtlink Electronics (also known as Shenzhen Zhibotong Electronics). The vulnerability, discovered in devices such as Electronics or ZBT). While the Zbtlink AX3000 Dual SIM 5G CPE WiFi 6 router, allows for unauthorized remote Linux control with root privileges. The implant functions by using initial discovery focused on the ‘ENDLESSDOORS’ implant, which provides unauthenticated root-shell access via a modified ‘rctl’ tool to act tool, subsequent research has identified additional factory-installed implants named ‘SPEAKINGSTONE’ and ‘DARKLANTERN’. ENDLESSDOORS, catalogued as both a client CVE-2026-66747, allows attackers to control devices and server, hiding among processes named ‘kworker’. Because the device initiates outbound connections, it can bypass firewalls connected network equipment by contacting a China-registered domain every 35 seconds. The hardware is distributed as OEM or ODM products under various brands, including Zbtlink and NAT Wiflyer. New findings reveal that DARKLANTERN operates via UDP port 9992, allowing arbitrary shell commands due to ineffective firewall settings. In one instance, the device made unauthorized connections even while on an isolated research network. SPEAKINGSTONE operates via UDP port 10000, enabling attackers to exfiltrate WAN PPPoE credentials, perform DNS hijacking, and establish reverse SSH tunnels. DARKLANTERN has been identified in 22 countries. Zbtlink has suspended sales of affected models and is developing patches, removed compromised firmware from its website, claiming the code was intended as an “after-sales technical-support tool,” though researchers argue it was deliberately hidden. tool.” Analysts estimate at least 100,000 routers are deployed worldwide. The discovery has prompted security advisories from Experts warn that the Canadian government and drawn attention only reliable mitigation is to existing U.S. FCC restrictions on Chinese consumer routers. disconnect devices from networks until clean firmware updates are available.

Versions

  1. 2026-08-28 13:09 UTC Zbtlink router ENDLESSDOORS and additional implant discovery
  2. 2026-08-10 19:05 UTC Zbtlink router ENDLESSDOORS backdoor discovery

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.