Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway

← Back to the feed

Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway

The Register · 7 hours ago

Chinese Wi-Fi router maker Zbtlink has denied claims that its devices contain a hidden backdoor, even as it quietly pulled firmware downloads to fix unspecified security vulnerabilities. The allegation came from threat-intelligence firm VulnCheck, whose CTO Jacob Baines said a Zbtlink router on his desk was continuously trying to reach a command-and-control server online, describing the behaviour as built in "because they were shipped that way" rather than the result of a hack. The row matters because it points to a router vendor potentially embedding covert remote-access tools in consumer and business networking hardware, raising fresh concerns about supply-chain security in widely used devices.

Baines named the alleged backdoor "ENDLESSDOORS", tracing it to an obscure command-and-control tool called rctl, uploaded to GitHub in January 2015 and never updated. He said the implant runs as a disguised root process, listens for instructions on port 7000, can execute shell commands or spawn a reverse shell, and communicates with no encryption, authentication or verification – meaning anyone on the network path, or in control of the target server, could hijack it. Zbtlink told The Register the function is only a maintenance tool for after-sales debugging on sample units and would not appear in mass-production firmware, but the firm's own download page, unlike a Wayback Machine snapshot from 31 July, now admits to detecting "firmware security vulnerabilities" and has pulled affected downloads for over 20 router models while patches are developed.

  • Zbtlink denies backdoor claims but pulls firmware over security flaws
  • VulnCheck says routers phone home to a command-and-control server
  • Firm's own download page contradicts its "no problem" denial

Business Markets

Read the full article at the source →