Massive Backdoor Discovered in Chinese Routers Sold Under Various Brands

A significant security vulnerability has been identified in a range of internet routers manufactured by Shenzhen Zhibotong Electronics, which are sold under multiple brand names, including Zbtlink and Wiflyer. This backdoor, dubbed ‘ENDLESSDOORS’ by cybersecurity firm VulnCheck, allows remote control of the affected devices by connecting to command and control servers located in China.

The backdoor operates by initiating outbound connections to these servers, enabling remote execution of commands without the need for the router to be directly accessible from the internet. This method bypasses traditional security measures, as the connection originates from within the network, making it challenging to detect and block.

VulnCheck’s analysis revealed that the backdoor is implemented through a tool called ‘rctl’ (remote control Linux), which was uploaded to GitHub in January 2015 and has remained largely unnoticed since. This tool facilitates the execution of shell commands and can spawn reverse bash shells, granting attackers extensive control over the compromised routers.

The affected models include, but are not limited to: CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and Z8102AX-2DSIM. Users are strongly advised to check their router’s model number and, if it matches any of the listed models, to disconnect and replace the device immediately.

This discovery underscores the ongoing security risks associated with network hardware, particularly devices sourced from manufacturers with limited transparency. The ability of the backdoor to initiate outbound connections and evade standard security protocols highlights the need for rigorous scrutiny of network equipment and the importance of sourcing devices from reputable vendors with a proven track record in security.