[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fehJYfrBPTwX1CCcm08aVrngF_x7dEegGyr_soxBXQFU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"4bde0055-5341-4cb9-8635-455ac91d640f","factory-installed-backdoor-in-zbtlink-routers-grants-unauthenticated-root-access","84c6986e-639b-43c4-97a2-ad39949b3a75","Factory-Installed Backdoor in Zbtlink Routers Grants Unauthenticated Root Access","Zbtlink routers shipped with a deliberate, factory-installed backdoor (ENDLESSDOORS) that provides unauthenticated root shell access and communicates with Chinese command-and-control infrastructure — meaning compromise begins the moment a device is powered on. This is a classic supply chain attack embedded at the firmware level, bypassing any post-deployment security controls entirely. The backdoor persisted across over two years of firmware images, indicating either intentional inclusion or a catastrophic failure in the vendor's secure development lifecycle. Organizations deploying these devices unknowingly handed adversaries persistent, privileged access to their networks with no user interaction required. This underscores why hardware and firmware provenance must be validated before any device is introduced into a production environment.","**Immediate actions:**\n- Identify and isolate all Zbtlink router models on your network pending further investigation or replacement.\n- Block outbound traffic from edge devices to unrecognized or suspicious IP ranges, particularly those associated with Chinese C2 infrastructure.\n- Perform firmware integrity checks on all network appliances using vendor-supplied hashes or trusted third-party analysis.\n\n**Long-term improvements:**\n- Establish a hardware and firmware vetting process that includes independent security review before deploying any new network device.\n- Maintain a complete, up-to-date inventory of all network appliances including make, model, firmware version, and country of origin.\n- Prioritize sourcing network infrastructure from vendors with transparent, auditable secure development lifecycle (SDL) practices.\n\n**Detection measures:**\n- Deploy network monitoring to detect anomalous outbound beacon traffic originating from edge devices or routers.\n- Implement network segmentation to ensure routers and other perimeter devices cannot freely communicate with internal critical assets.\n- Use a SIEM or NDR solution to alert on unauthenticated shell activity or unexpected management-plane connections on network devices.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 1: Inventory and Control of Enterprise Assets","CIS Control 12: Network Infrastructure Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-161: Supply Chain Risk Management Practices","NIST AC-3: Access Enforcement","NIST AC-17: Remote Access","NIST SI-7: Software, Firmware, and Information Integrity","NIST SR-3: Supply Chain Controls and Processes","ISO\u002FIEC 27001 A.12.6: Technical Vulnerability Management","ISO\u002FIEC 27001 A.15.1: Information Security in Supplier Relationships","ITIL: Supplier Management Practice","published","2026-08-06T10:21:49.439769+00:00","2026-08-06T10:21:49.135+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fchinese-made-zbtlink-routers-ship-with.html","chinese-made-zbtlink-routers-ship-with-backdoor-that-opens-unauthenticated-root--869ad8","Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"b4a0d88a-cf11-46d6-886f-96dadad94438","2026-08-06","afternoon","ThreatNoir Afternoon Brief — August 6","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-06\u002Fthreatnoir-afternoon-brief-2026-08-06.mp3"]