Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
Chinese Wi-Fi router maker Zbtlink has denied claims that its devices contain a hidden backdoor, even as it quietly pulled firmware downloads to fix unspecified security vulnerabilities. The allegation came from threat-intelligence firm VulnCheck, whose CTO Jacob Baines said a Zbtlink router on his desk was continuously trying to reach a command-and-control server online, describing the behaviour as built in "because they were shipped that way" rather than the result of a hack. The row matters because it points to a router vendor potentially embedding covert remote-access tools in consumer and business networking hardware, raising fresh concerns about supply-chain security in widely used devices.
Baines named the alleged backdoor "ENDLESSDOORS", tracing it to an obscure command-and-control tool called rctl, uploaded to GitHub in January 2015 and never updated. He said the implant runs as a disguised root process, listens for instructions on port 7000, can execute shell commands or spawn a reverse shell, and communicates with no encryption, authentication or verification – meaning anyone on the network path, or in control of the target server, could hijack it. Zbtlink told The Register the function is only a maintenance tool for after-sales debugging on sample units and would not appear in mass-production firmware, but the firm's own download page, unlike a Wayback Machine snapshot from 31 July, now admits to detecting "firmware security vulnerabilities" and has pulled affected downloads for over 20 router models while patches are developed.
- Zbtlink denies backdoor claims but pulls firmware over security flaws
- VulnCheck says routers phone home to a command-and-control server
- Firm's own download page contradicts its "no problem" denial