Chinese-made Zbtlink routers have backdoor, researchers say
VulnCheck said the firmware implant could let a server in China fully control affected routers, with about 100,000 devices deployed worldwide, Baines said.
- Cybersecurity firm VulnCheck reported that Zbtlink routers are shipped with built-in firmware backdoors; implants automatically communicate with servers in China, potentially allowing unauthorized device control.
- VulnCheck Chief Technology Officer Jacob Baines estimates 100,000 units are deployed worldwide, primarily in business networks, with the implant operating without internet exposure to grant remote access.
- Baines noted manufacturers often rebrand Chinese hardware to appear as if they originate from South Korea or Germany, and these routers are sold globally under Zbtlink and Wiflyer brand names, including on Amazon.
- The Federal Communications Commission instituted a blanket ban on new foreign-made routers in March, while Texas sued TP-Link in February, alleging its devices launched cyberattacks.
- Experts describe the discovery as a 'smoking gun' for claims that Chinese-made routers cannot be trusted, and Zbtlink did not immediately respond to CNET's requests for comment.
24 Articles
24 Articles
Chinese router manufacturer Zbtlink Electronics (hereinafter Zbtlink) has suspended sales of its routers in which a "backdoor" allowing remote access was discovered and has begun security updates. Amid growing security concerns surrounding Chinese-made network equipment, vigilance regarding vulnerabilities to external attacks (hacking) related to this issue appears to be continuing. On the 6th (
Maybe the FCC was onto something: These routers are phoning home to China with a secret backdoor
TL;DR A new report details a massive security flaw in Zbtlink-made routers. The routers are programmed to ping a hard-coded list of servers, traced back to China. Once connected, the routers grant full root access — no authentication required. This past spring, the FCC announced a sweeping ban on new foreign-made routers — like the kind you use to get online with your ISP and connect all your devices to Wi-Fi. This was all done in the name of n…
Another top router maker accused of firmware having backdoors — Chinese giant Zbtlink halts downloads to fix issue
VulnCheck CTO Jacob Baines reported Zbtlink routers shipped with a built‑in backdoor dubbed ENDLESSDOORS, allowing remote root commands and reverse shellsZbtlink denied malicious intent, calling it an after‑sales maintenance feature, but quietly pulled vulnerable firmware and promised patchesResearchers warn all firmware images are hijackable; mitigation advice is to replace devices or enforce strict egress controls and treat LAN as untrustedChi…
Think Before Buying: Hidden backdoor found in 20+ Chinese Router models, warns cybersecurity firm VulnCheck
New Delhi: A cybersecurity investigation has uncovered a hidden backdoor in more than 20 models of Chinese-made wireless routers sold across global markets, raising fresh concerns over the security of networking equipment manufactured by Chinese companies. The discovery, announced on August 5 by cybersecurity firm VulnCheck, comes amid increasing Western scrutiny of Chinese technology products and follows a series of regulatory actions in the Un…
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium


















