Hidden Backdoor Found in Over 20 Zbtlink Router Models

Recent investigations have uncovered a concealed backdoor in more than 20 models of Zbtlink routers, devices widely used in homes, offices, and various mobile settings. This discovery raises significant security concerns, as these routers serve as critical gateways between local networks and the internet.

The backdoor, identified as ENDLESSDOORS and assigned CVE-2026-66747, is embedded within the firmware of the affected routers. Unlike typical malware that requires user interaction or exploits vulnerabilities, ENDLESSDOORS autonomously initiates communication with external servers upon device startup, awaiting further instructions. This behavior allows it to bypass standard firewall protections, making detection and prevention more challenging.

Security researchers at VulnCheck analyzed firmware images from over 20 Zbtlink models and found that the backdoor operates under the guise of ‘kworker,’ a name usually associated with legitimate Linux processes. However, in this context, ‘kworker’ runs with root privileges, consumes system resources, and establishes outbound connections using a modified version of the remote-control utility ‘rctl.’ The backdoor communicates with external servers without proper authentication, sending registration messages that include a label and the router’s LAN MAC address. This setup enables remote operators to execute commands with full administrative control or initiate interactive sessions on the compromised device.

The implications of this backdoor are profound. Attackers with control over these routers can monitor and manipulate network traffic, alter device configurations, and potentially infiltrate connected systems. Given the routers’ role as intermediaries between local networks and the broader internet, such unauthorized access poses a substantial risk to data integrity and network security.

Compounding the issue, there is currently no confirmed clean firmware available for the affected models. This situation necessitates immediate action from organizations and individuals using these devices. It is crucial to identify and assess all routers by their specific model numbers, including those deployed in remote locations, mobile units, or by third-party contractors. Devices operating on cellular networks should receive particular scrutiny due to their potential exposure.

Administrators with access to these routers should inspect running processes for unbracketed ‘kworker’ entries and monitor for outbound traffic on TCP ports 7000 and 7001, which are associated with the backdoor’s communication channels. Blocking and alerting on connections to known malicious destinations is advisable. However, given the compromised nature of the firmware, such measures may not fully mitigate the risk.

In light of these findings, replacing the affected routers is the most effective course of action. If immediate replacement is not feasible, isolating these devices behind stringent outbound controls and segregating their local networks can help contain potential threats. Security teams should also preserve logs and document the models and firmware versions of all devices for further analysis and remediation planning.

This incident underscores the critical importance of supply chain security in networking hardware. The presence of a hidden backdoor in widely distributed routers highlights the need for rigorous security assessments and continuous monitoring of network devices. Organizations must remain vigilant, ensuring that all components of their network infrastructure are free from unauthorized modifications that could compromise overall security.