What happened
Researchers at the security firm VulnCheck, led by CTO Jacob Baines, disclosed a factory-installed backdoor running on at least 20 router models made by the Chinese manufacturer Zbtlink, including the CPE2801, WE1026-5G-WD, WE2416, WG2107 and Z8102AX-2DSIM, spanning 21 different firmware versions. The implant, which VulnCheck named ENDLESSDOORS, starts automatically when the router boots and tries to reach command-and-control servers roughly every 35 seconds, including a hardcoded IP address and a domain tied to the operation. It's built on a customized version of a tool called rctl, remote control linux, that lets an attacker execute commands or open a full root shell on the device without ever logging in. Because the backdoor runs with root privileges and masks itself as a normal Linux process, a compromised router would look completely normal to anyone checking it casually. Zbtlink has said the access was 'solely intended' for after-sales maintenance, but the company has paused sales of the affected models while it develops patched firmware.
Why it matters for your business
Zbtlink routers are inexpensive and sold under multiple brand names through general retail and online marketplaces, which is exactly the kind of hardware a small office picks up to save money on networking gear. A backdoor at this level isn't a bug you patch with an update from the vendor's app, it's built into the firmware from the factory, meaning the device was never trustworthy to begin with. Any business running one of the affected models has, in effect, been running a router that a third party could access and control at any time without leaving obvious signs.
What to do
Check your office router's make and model against Zbtlink's affected list, and if it's a match, take it off your network until a patched firmware version is confirmed available and installed, or replace it outright. For new purchases, stick to business-grade networking gear from vendors with a track record of prompt security patching rather than the cheapest option on a marketplace listing.
