Zbtlink Routers Found with Backdoor Named ENDLESSDOORS

Zbtlink Routers Found with Backdoor Named ENDLESSDOORS

First seen 6 Aug 2026, 07:21 UTC Theregisterwww.vulncheck.com 71% similarity 71.0

Article Content

Browse articles
ThreatCluster

Zbtlink routers have been identified with a backdoor named ENDLESSDOORS, which allows remote command execution. This issue was reported by VulnCheck's CTO Jacob Baines, who found the routers continuously attempting to connect to a command and control server. The backdoor is based on a tool called rctl, which was uploaded to GitHub in 2015 and allows for executing commands as root without verification. Zbtlink has denied the existence of backdoors in their firmware but has paused firmware downloads to address unspecified security vulnerabilities. The vulnerability affects multiple router models, and the company claims the feature is for after-sales maintenance, not intended for mass production. CVE-2026-66747 was published on August 5, 2026, highlighting the ongoing security concerns.

Key Points: • Zbtlink routers contain a backdoor named ENDLESSDOORS, allowing remote command execution. • The backdoor utilizes a tool called rctl, which executes commands without verification. • Zbtlink has paused firmware downloads to address security vulnerabilities amid the allegations.

ThreatCluster AI How this analysis works

Timeline

2026-08-05
CVE-2026-66747 published
CVE-2026-66747 was published, highlighting vulnerabilities in Zbtlink routers.
VulnCheck
2026-08-06
Zbtlink denies backdoor allegations
Zbtlink claims that the feature is for maintenance purposes and not a backdoor, while pausing firmware downloads.
The Register
2026-08-06
VulnCheck reports backdoor in Zbtlink routers
VulnCheck's CTO Jacob Baines reported that Zbtlink routers are shipped with a backdoor that connects to command and control servers.
VulnCheck

Community

Browse all →