Chinese Router Vendor Zbtlink Denies Backdoor Claims Amid Firmware Download Pause
Chinese router vendor Zbtlink is temporarily halting firmware downloads after researchers claimed its devices contain a backdoor, which the company denies.

Researchers at VulnCheck have identified what they describe as a backdoor, dubbed "ENDLESSDOORS," embedded within the firmware of Zbtlink routers. According to VulnCheck's CTO Jacob Baines, this backdoor, implemented as a tool named rctl (remote control Linux), allows for remote command execution and communication with command and control (C2) servers without authentication. Baines stated that the tool continuously attempts to connect to internet-based C2 servers, suggesting it was intentionally included rather than a result of a compromise.
The alleged backdoor operates by running as a root process within the Linux kernel, making it difficult to detect. Baines detailed that the rctl component connects to specific internet endpoints, including rbdg4nzqadui[.]wikaba[.]com, sending a simple 39-byte registration message consisting of a class label and the device's MAC address. This lack of a secure handshake or verification mechanism means that any entity controlling one of these endpoints, or intercepting traffic along the network path, could potentially hijack the communication and control the affected router.
Zbtlink has responded to the allegations by denying the existence of a backdoor, asserting that the code identified by VulnCheck is solely for after-sales maintenance and debugging purposes. The company claims this feature is typically retained only on sample units for customer support and is not included in mass-production shipments. This explanation, however, appears to contradict the company's own public statements.
Following the accusations, Zbtlink temporarily removed firmware downloads from its website, citing "firmware security vulnerabilities affecting selected router firmware releases." This action was framed as a precautionary measure while an engineering team works on secured patched firmware. The temporary removal of downloads, coupled with the company's denial of a backdoor, has raised questions about the true nature of the security issues.
VulnCheck's analysis indicates that the affected devices phone home to only four endpoints, with one using a domain name directly linked to Zbtlink, which Baines described as "damning." The researchers noted that Zbtlink routers are sold under various brand names, including ZBT, ZBTWiFi, and Wiflyer, and are available through major e-commerce platforms, suggesting a potentially wide reach for any vulnerabilities.
Baines opted not to follow standard coordinated disclosure protocols, arguing that the alleged backdoor was an intentional inclusion by the vendor, not a bug requiring a patch. He stated that informing the vendor would not benefit owners of the devices and would instead alert those operating the C2 infrastructure.
Zbtlink specializes in OEM and ODM customization services, allowing customers to implement their own software, which could further complicate the security landscape. The company has previously promoted its use of the OpenWrt open-source firmware, which supports at least one Zbtlink product, indicating a flexible approach to firmware development that could potentially allow for the inclusion of custom, less-vetted code.
Given the potential for supply chain attacks targeting router firmware, the findings by VulnCheck and Zbtlink's subsequent actions highlight significant concerns for users of these devices. Researchers recommend blocking access to the identified endpoints and suggest replacing affected devices or isolating them behind strict network controls.