Skip to content
Zbtlink Routers Found with Backdoor Named ENDLESSDOORS

Zbtlink Routers Found with Backdoor Named ENDLESSDOORS

First seen 6 Aug 2026, 07:21 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 7, 2026 at 03:27 UTC
  • •Zbtlink routers contain a backdoor named ENDLESSDOORS, allowing remote command execution.
  • •The backdoor utilizes a tool called rctl, which executes commands without verification.
  • •Zbtlink has paused firmware downloads to address security vulnerabilities amid the allegations.

Zbtlink routers have been identified with a backdoor named ENDLESSDOORS, which allows remote command execution. This issue was reported by VulnCheck's CTO Jacob Baines, who found the routers continuously attempting to connect to a command and control server. The backdoor is based on a tool called rctl, which was uploaded to GitHub in 2015 and allows for executing commands as root without verification. Zbtlink has denied the existence of backdoors in their firmware but has paused firmware downloads to address unspecified security vulnerabilities. The vulnerability affects multiple router models, and the company claims the feature is for after-sales maintenance, not intended for mass production. CVE-2026-66747 was published on August 5, 2026, highlighting the ongoing security concerns.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 55d ago How this analysis works

Timeline

2026-08-05
CVE-2026-66747 published
CVE-2026-66747 was published, highlighting vulnerabilities in Zbtlink routers.
VulnCheck
2026-08-06
Zbtlink denies backdoor allegations
Zbtlink claims that the feature is for maintenance purposes and not a backdoor, while pausing firmware downloads.
The Register
2026-08-06
VulnCheck reports backdoor in Zbtlink routers
VulnCheck's CTO Jacob Baines reported that Zbtlink routers are shipped with a backdoor that connects to command and control servers.
VulnCheck

More articles in this cluster (6)

Following this threat?

Track Endlessdoors, Asus and CVE-2026-66747 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed