Zbtlink denies backdoor in routers while halting firmware downloads for fixes
Chinese router maker Zbtlink says its devices have no hidden backdoors, yet it temporarily removed firmware downloads to address undisclosed security flaws.
Threat-intelligence firm VulnCheck, through its chief technology officer Jacob Baines, alleged that Zbtlink routers embed a backdoor named ENDLESSDOORS, which repeatedly reaches out to a specific server and can execute remote commands. Zbtlink refuted the accusation, describing the code as a standard after-sales maintenance tool retained only on prototype units for debugging purposes and not shipped in mass production.
However, a later update on Zbtlink’s firmware download site announced the temporary removal of affected firmware releases while security patches are being developed, implicitly acknowledging vulnerabilities. The vendor highlighted that its hardware is often re-flashed with custom firmware, frequently using the open-source OpenWrt project. Baines warned that the implants lack authentication, making them susceptible to hijacking, and advised users to either replace the routers or isolate them behind strict egress controls. The episode raises concerns about potential supply-chain attacks on network equipment.
Why it matters
Compromised router firmware can expose home and business networks to remote control and data theft.
In this story