news.mlab.sh
Back to the feed
threat-intel

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

High
Image: The Hacker News
Summary

Chinese router manufacturer Zbtlink ships router firmware with a factory-installed backdoor, dubbed "ENDLESSDOORS," that automatically attempts to connect to command-and-control infrastructure every 35 seconds. This backdoor, implemented through a root shell, allows attackers to gain remote control of the router without requiring internet access. Zbtlink has temporarily removed affected firmware versions and is working on patched versions. The vulnerability affects a wide range of models and requires users to actively monitor their systems for malicious files and block associated egress points.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.