@UKTechHub
.
.

Hidden Backdoor Found in More Than 20 Router Models Published: 15 August 2026 A serious security concern has emerged involving more than 20 router models manufactured by Chinese networking company Zbtlink. Cybersecurity researchers at VulnCheck discovered a hidden component,…

UKTH forums 🛜 Wireless Routers & Modems ISP Kit/Other Stuff etc. Hidden Backdoor Found in More Than 20 Router Models Published: 15 August 2026 A serious security concern has emerged involving more than 20 router models manufactured by Chinese networking company Zbtlink. Cybersecurity researchers at VulnCheck discovered a hidden component,...

NEWS
Viewing 1 post (of 1 total)
  • Author
    Posts
  • #43197
    UK SentinelUK Sentinel
    Keymaster
    • Replies 8,639
    • The Skipper

    Published: 15 August 2026

    A serious security concern has emerged involving more than 20 router models manufactured by Chinese networking company Zbtlink.

    Cybersecurity researchers at VulnCheck discovered a hidden component, named ENDLESSDOORS, within the firmware of affected Zbtlink routers. The component runs with root-level privileges and can establish an outbound connection to external servers, potentially allowing remote commands to be executed on the router.

    The affected hardware has reportedly been sold worldwide under both Zbtlink and Wiflyer branding. VulnCheck identified the backdoor in 20 router models and estimates that at least 100,000 devices could be in use globally.

    The concern is particularly serious because the functionality is built into the router firmware itself. ENDLESSDOORS starts automatically and communicates outwards, meaning an attacker does not necessarily need the router to be directly accessible from the internet.

    Researchers demonstrated that the component could provide an attacker with root-level control, including the ability to execute commands and obtain an interactive shell on an affected router.

    The vulnerability has been assigned CVE-2026-66747, with a CVSS severity score of 9.3.

    Zbtlink has responded to the disclosure and is working on the issue. Anyone using a Zbtlink, Wiflyer or potentially rebranded version of the affected hardware should check the exact model and firmware version.

    A simple change of the router’s administrator password should not be considered a complete solution if the affected firmware is installed, as the issue exists within the firmware itself.

    Source: VulnCheck – ENDLESSDOORS Is Phoning Home

    CVE information: NIST National Vulnerability Database – CVE-2026-66747

    In a completely sane world, madness is the only freedom (J.G.Ballard).

Viewing 1 post (of 1 total)
  • You must be logged in to reply to this topic.
Latest Posts