Critical Zbtlink Router Backdoor Affects 20+ Models
Key Takeaways Over 20 models of Zbtlink routers, widely distributed globally, contain a pre-installed backdoor dubbed “ENDLESSDOORS.” The backdoor, identified as CVE-2026-66747, initiates...
Key Takeaways
- Over 20 models of Zbtlink routers, widely distributed globally, contain a pre-installed backdoor dubbed “ENDLESSDOORS.”
- The backdoor, identified as CVE-2026-66747, initiates at device boot-up and grants full administrative control to a remote attacker.
- Unlike traditional vulnerabilities, ENDLESSDOORS actively connects to external command-and-control servers, bypassing typical inbound firewall protections.
- No official firmware patch is available, making device replacement or stringent isolation the primary mitigation strategies.
A critical backdoor has been uncovered in Zbtlink routers, devices frequently deployed in a variety of environments, including homes, businesses, temporary installations, and vehicles worldwide. This hidden remote-control implant, dubbed “ENDLESSDOORS,” transforms these network gateways into significant security risks, potentially allowing unauthorized access and control.
Table Of Content
The presence of ENDLESSDOORS means that an otherwise trusted piece of network hardware could serve as a persistent entry point into an organization’s or individual’s network infrastructure. This discovery is particularly concerning given the widespread use of affordable, compact network hardware like Zbtlink routers.
Unlike many vulnerabilities that require user interaction or a direct breach, ENDLESSDOORS operates by initiating an outbound connection from the router to external infrastructure, awaiting instructions. This design allows it to circumvent conventional inbound firewall rules, presenting a unique challenge for detection and mitigation.
Security researchers at VulnCheck said in a report that they identified the malicious code within the firmware images of more than 20 distinct Zbtlink router models. This issue has been assigned the identifier CVE-2026-66747. The report highlights that the component executes immediately upon boot, enabling attackers to issue commands with full administrative privileges on the compromised device.
The implications of such a backdoor are severe. Routers occupy a pivotal position between internal networks and the internet. A hostile entity could leverage this access to intercept network traffic, infiltrate deeper into the local network, alter device configurations, or deploy additional malicious tools. Previous incidents involving persistent footholds in SOHO devices underscore the long-term value that compromised edge devices can offer to attackers.
Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor
The clandestine component masquerades as kworker, a process name typically associated with legitimate Linux kernel operations. However, on affected Zbtlink routers, this suspicious kworker process is not a standard system thread. It runs with root privileges, manages its own memory, and establishes an outbound connection using a modified version of the legacy remote-control utility, rctl.
The remote connection established by ENDLESSDOORS is particularly dangerous due to its lack of robust authentication. Upon connecting to its designated server, the implant transmits a brief registration message containing a label and the router’s LAN MAC address. The server can then transmit commands for the device to execute as root, or even request an interactive shell, granting direct command-line access.
Unlike vulnerabilities that demand complex exploit chains, this backdoor merely requires an attacker to control or intercept the destination domain that the router is hardcoded to trust. No user action is necessary for exploitation, as the router proactively initiates the connection.
The report indicates that any entity capable of manipulating the domain’s DNS resolution could seize control of an implant attempting to connect. This outbound communication design is particularly insidious, as it allows the router to reach command infrastructure even if it’s behind NAT and common outbound filtering, without exposing any management ports to the public internet. This escalating risk is compounded by the record-high levels of router scanning, making monitoring outbound traffic as crucial as securing inbound access.
The researchers confirmed the presence of the ENDLESSDOORS implant across 21 distinct firmware images. These images correspond to various Zbtlink devices, including CPE2801, WE-series, WG-series, and Z8102AX-2DSIM models. It is important to note that the specific model number is more indicative than the brand label, as identical hardware and firmware can be rebranded and sold under different names. Therefore, the current list of affected models may not be exhaustive, and other rebranded or unbranded units could also be at risk.
What You Should Do
- Identify Affected Devices: Prioritize identifying Zbtlink routers by their model number across all deployment locations, including remote offices, vehicle fleets, and contractor sites. Exercise extreme caution with any unknown cellular CPE devices.
- Monitor for IoCs: Actively search for unbracketed
kworkerprocesses and the associated files listed in the Indicators of Compromise (IoCs) table below. - Block and Alert on C2 Traffic: Implement firewall rules to block and generate alerts for any outbound traffic on TCP ports 7000 and 7001 originating from network device segments, targeting the listed command-and-control domains and IP addresses.
- Isolate or Replace: As no clean firmware is currently available, the most secure action is to replace affected devices, especially those handling critical traffic. If immediate replacement is not feasible, isolate these devices behind strict outbound controls and ensure their local network segment is completely separate from other sensitive networks.
- Preserve Evidence: Before removing any compromised unit, collect and preserve logs, noting the model, firmware name, process states, and any relevant network events.
- Avoid Simple Disabling: Do not rely solely on disabling the backdoor’s startup script. Firmware that shipped with a hidden remote-control function may harbor other undisclosed vulnerabilities. Replacing the equipment is a more secure long-term solution.
Indicators of Compromise (IoCs)
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
| Type | Indicator | Description |
|---|---|---|
| Domain | zbtctl.epplink[.]net |
Primary ENDLESSDOORS command-and-control domain |
| IP address | 47.100.190[.]96 |
Resolution for zbtctl.epplink[.]net |
| IP address | 47.107.224[.]89 |
Hardcoded command-and-control address |
| Domain | online-string[.]com |
Secondary command-and-control domain |
| IP address | 45.32.81[.]152 |
Resolution for online-string[.]com |
| Domain | rbdg4nzqadui[.]wikaba[.]com |
Secondary command-and-control domain |
| IP address | 43.248.136[.]125 |
Resolution for rbdg4nzqadui[.]wikaba[.]com |
| File path | /usr/sbin/kworker |
ENDLESSDOORS implant binary |
| File path | /usr/lib/librctl.so |
Related remote-control library |
| File path | /etc/kworker.cfg |
Implant configuration file |
| File path | /etc/init.d/skworker |
Startup script used to launch the implant |
| Network port | TCP/7000 |
Implant check-in and command channel |
| Network port | TCP/7001 |
Interactive shell connection |
| Command string | rctlbash |
String that requests an interactive root shell |
| Firmware file / SHA-256 | CPE2801_V22.10.09.bin / b3956cfbebf9c8d0b2c7a2ecbe59e71c31a5802f2084d25d93a984c0f811e2c7 |
Affected firmware image |
| Firmware file / SHA-256 | WE1026-5G-WD_V21.04.07.bin / f961e4243e759453294340bc7d1b145016d70b97ab328caf47c64ea3cd818148 |
Affected firmware image |
| Firmware file / SHA-256 | WE1326_V22.02.18_1.bin / 7791de11cd27cb596deff089904a6eab3a7e0aa391f867c2389582d5c78fef4c |
Affected firmware image |
| Firmware file / SHA-256 | WE2007_V23.08.12.bin / 6926f919da7f4447229f49842266d884369e1587df655149673e46f1d8787e47 |
Affected firmware image |
| Firmware file / SHA-256 | WE2008-DSIM_V23.08.11.bin / 09ed9ad3ac886f5aaf8357127b6dd5926bd4af1e2cc687a6a4856bcaedee2667 |
Affected firmware image |
| Firmware file / SHA-256 | WE2416_V21.03.22_1.bin / 76a17581bbde4c0550e8f4abfd903923aceeb50dc69dae4dd904628c273b90ee |
Affected firmware image |
| Firmware file / SHA-256 | WE2416_V21.03.22.bin / 76a17581bbde4c0550e8f4abfd903923aceeb50dc69dae4dd904628c273b90ee |
Affected firmware image |
| Firmware file / SHA-256 | WE3326_V20.09.30.bin / f5a94e536a1cac8552fb9c327c4bac6017e034786be98cc402a149cb51250d8f |
Affected firmware image |
| Firmware file / SHA-256 | WE826-T3-DSIM_V21.12.21.bin / b3e667235e9b41b8fc3594edaa64879750e7f75d7518fff7514d55837430411a |
Affected firmware image |
| Firmware file / SHA-256 | WG108_V21.08.06_1.bin / 37efadf0f4a110be0145139a43ebd032abb5b27b79b1eb2ab3578dcd31655a9e |
Affected firmware image |
| Firmware file / SHA-256 | WG1602_V23.10.11.bin / f019d03c2489b2bc486d71e355e07f8f2862dff078574a8662a5a45932e7e453 |
Affected firmware image |
| Firmware file / SHA-256 | WG1608-DSIM_V23.03.16.bin / 73a0d95b8e23c7780cd91e978238c6db519665b05481fb228b4db9a9ec99c8ae |
Affected firmware image |
| Firmware file / SHA-256 | WG209_V21.07.28.bin / efc8a8ead69c63ecfffd883cfbe6bd131082aa13c0d3b324c00d79f4c149bd92 |
Affected firmware image |
| Firmware file / SHA-256 | WG2105_V22.05.30.bin / 1545169fa8a3ae182d8e39aca8ec6cb6849b864e38646f29017232813e397e77 |
Affected firmware image |
| Firmware file / SHA-256 | WG259_V21.03.23.bin / b4fda77e082fbf961db02273999e92e715e1824140ea92b2ab30163338b6622b |
Affected firmware image |
| Firmware file / SHA-256 | WG3526_V22.11.01.bin / 2d558bc9a6c7e7480e946f1c0524a651554887a1c563d7633f1903d06ff493fb |
Affected firmware image |
| Firmware file / SHA-256 | Z8102AX-2DSIM-..._174431.bin / dcdaa1fe80707b8d8fde8ad36c3e62a53623aff09bf5ccc544d4c1a1a54208b8 |
Affected firmware image |
| Firmware file / SHA-256 | ZBT-WE5927_V22.08.10.bin / 4f5d8319b4bad5d9243496c1358fda4783ea9a0865c32881b3f57ecedb879570 |
Affected firmware image |
| Firmware file / SHA-256 | ZBT-WE5931AC_V22.05.31.bin / dee3908280b91cb7ad60c69c1d34c599ceed7c8c66c025851e5831482815b271 |
Affected firmware image |
| Firmware file / SHA-256 | ZBT-WE5931_V22.05.31.bin / 47d8ffb3a9a3fe0337e3c1e355fab4847dd61952fbe9aad98aadede489ca31fd |
Affected firmware image |
| Firmware file / SHA-256 | ZBT-WG2107_V22.09.08.bin / 71b20ebff0630b33c96bef320adc75901b34f1fd2cc9af974cf93ff37d102ec8 |
Affected firmware image |
kworker SHA-256 |
dc1f4056af20677bdc7294ae4707f0c7bdfc85d8b57db212b622b9dc09c92731 |
Observed in CPE2801, WE3326, WE826-T3-DSIM, ZBT-WE5927, ZBT-WE5931AC and ZBT-WE5931 |
kworker SHA-256 |
33f8c0532100eeb10213d167e5eb483394a7e43bf6d276441a1573360622011a |
Observed in WE1026-5G-WD |
kworker
|



No Comment! Be the first one.