Factory-Installed Backdoor in Zbtlink Routers Grants Unauthenticated Root Access
Zbtlink routers shipped with a deliberate, factory-installed backdoor (ENDLESSDOORS) that provides unauthenticated root shell access and communicates with Chinese command-and-control infrastructure — meaning compromise begins the moment a device is powered on. This is a classic supply chain attack embedded at the firmware level, bypassing any post-deployment security controls entirely. The backdoor persisted across over two years of firmware images, indicating either intentional inclusion or a catastrophic failure in the vendor's secure development lifecycle. Organizations deploying these devices unknowingly handed adversaries persistent, privileged access to their networks with no user interaction required. This underscores why hardware and firmware provenance must be validated before any device is introduced into a production environment.
Tactical Insight
Immediate actions
- Identify and isolate all Zbtlink router models on your network pending further investigation or replacement.
- Block outbound traffic from edge devices to unrecognized or suspicious IP ranges, particularly those associated with Chinese C2 infrastructure.
- Perform firmware integrity checks on all network appliances using vendor-supplied hashes or trusted third-party analysis.
Long-term improvements
- Establish a hardware and firmware vetting process that includes independent security review before deploying any new network device.
- Maintain a complete, up-to-date inventory of all network appliances including make, model, firmware version, and country of origin.
- Prioritize sourcing network infrastructure from vendors with transparent, auditable secure development lifecycle (SDL) practices.
Detection measures
- Deploy network monitoring to detect anomalous outbound beacon traffic originating from edge devices or routers.
- Implement network segmentation to ensure routers and other perimeter devices cannot freely communicate with internal critical assets.
- Use a SIEM or NDR solution to alert on unauthenticated shell activity or unexpected management-plane connections on network devices.