Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Chinese router manufacturer Zbtlink ships router firmware with a factory-installed backdoor, dubbed "ENDLESSDOORS," that automatically attempts to connect to command-and-control infrastructure every 35 seconds. This backdoor, implemented through a root shell, allows attackers to gain remote control of the router without requiring internet access. Zbtlink has temporarily removed affected firmware versions and is working on patched versions. The vulnerability affects a wide range of models and requires users to actively monitor their systems for malicious files and block associated egress points.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
