Researchers report backdoor in Zbtlink routers affecting thousands of devices
Cybersecurity researchers at VulnCheck have identified a backdoor in more than 20 models of Zbtlink routers that could allow remote access to affected devices and potentially other systems connected to the same network.
Cybersecurity firm VulnCheck has reported that more than 20 models of routers manufactured and sold by Chinese company Zbtlink contain a previously undocumented backdoor that could enable unauthorised access to devices and networks.
According to Jacob Baines, chief technology officer at VulnCheck, who discovered the issue, the backdoor, named ‘Endlessdoors’ by the researchers, was found in routers sold under the Zbtlink and Wiflyer brand names. Baines estimated that at least 100,000 affected routers may be deployed worldwide, although the exact number and locations of active devices remain unclear.
VulnCheck researchers said the backdoor causes affected routers to communicate with a specific IP address and a China-registered domain approximately every 35 seconds. They warned that whoever controls those domains could potentially gain control of the routers and access other devices connected to the same network.
Zbtlink did not respond to Reuters’ request for comment. Reuters also reported that it could not determine why the backdoor exists, whether it was intentionally introduced, or whether it has previously been exploited.
