Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Papyrus Ad Fraud Abuses Hidden WebViews to Fake User Engagement
August 7, 2026
Critical Flaws in Enterprise Java Platforms Let Attackers Execute Remote Code
August 7, 2026
Kimi K3 AI Model Sandbox Escape Exposes Sensitive Data
August 7, 2026
Home/Threats/Critical Zbtlink Router Backdoor Affects 20+ Models
Threats

Critical Zbtlink Router Backdoor Affects 20+ Models

Key Takeaways Over 20 models of Zbtlink routers, widely distributed globally, contain a pre-installed backdoor dubbed “ENDLESSDOORS.” The backdoor, identified as CVE-2026-66747, initiates...

Sarah simpson
Sarah simpson
August 7, 2026 5 Min Read
3 0

Key Takeaways

  • Over 20 models of Zbtlink routers, widely distributed globally, contain a pre-installed backdoor dubbed “ENDLESSDOORS.”
  • The backdoor, identified as CVE-2026-66747, initiates at device boot-up and grants full administrative control to a remote attacker.
  • Unlike traditional vulnerabilities, ENDLESSDOORS actively connects to external command-and-control servers, bypassing typical inbound firewall protections.
  • No official firmware patch is available, making device replacement or stringent isolation the primary mitigation strategies.

A critical backdoor has been uncovered in Zbtlink routers, devices frequently deployed in a variety of environments, including homes, businesses, temporary installations, and vehicles worldwide. This hidden remote-control implant, dubbed “ENDLESSDOORS,” transforms these network gateways into significant security risks, potentially allowing unauthorized access and control.

Table Of Content

  • Key Takeaways
  • Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor
  • What You Should Do
  • Indicators of Compromise (IoCs)

The presence of ENDLESSDOORS means that an otherwise trusted piece of network hardware could serve as a persistent entry point into an organization’s or individual’s network infrastructure. This discovery is particularly concerning given the widespread use of affordable, compact network hardware like Zbtlink routers.

Unlike many vulnerabilities that require user interaction or a direct breach, ENDLESSDOORS operates by initiating an outbound connection from the router to external infrastructure, awaiting instructions. This design allows it to circumvent conventional inbound firewall rules, presenting a unique challenge for detection and mitigation.

Security researchers at VulnCheck said in a report that they identified the malicious code within the firmware images of more than 20 distinct Zbtlink router models. This issue has been assigned the identifier CVE-2026-66747. The report highlights that the component executes immediately upon boot, enabling attackers to issue commands with full administrative privileges on the compromised device.

The implications of such a backdoor are severe. Routers occupy a pivotal position between internal networks and the internet. A hostile entity could leverage this access to intercept network traffic, infiltrate deeper into the local network, alter device configurations, or deploy additional malicious tools. Previous incidents involving persistent footholds in SOHO devices underscore the long-term value that compromised edge devices can offer to attackers.

Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor

The clandestine component masquerades as kworker, a process name typically associated with legitimate Linux kernel operations. However, on affected Zbtlink routers, this suspicious kworker process is not a standard system thread. It runs with root privileges, manages its own memory, and establishes an outbound connection using a modified version of the legacy remote-control utility, rctl.

The remote connection established by ENDLESSDOORS is particularly dangerous due to its lack of robust authentication. Upon connecting to its designated server, the implant transmits a brief registration message containing a label and the router’s LAN MAC address. The server can then transmit commands for the device to execute as root, or even request an interactive shell, granting direct command-line access.

Unlike vulnerabilities that demand complex exploit chains, this backdoor merely requires an attacker to control or intercept the destination domain that the router is hardcoded to trust. No user action is necessary for exploitation, as the router proactively initiates the connection.

The report indicates that any entity capable of manipulating the domain’s DNS resolution could seize control of an implant attempting to connect. This outbound communication design is particularly insidious, as it allows the router to reach command infrastructure even if it’s behind NAT and common outbound filtering, without exposing any management ports to the public internet. This escalating risk is compounded by the record-high levels of router scanning, making monitoring outbound traffic as crucial as securing inbound access.

The researchers confirmed the presence of the ENDLESSDOORS implant across 21 distinct firmware images. These images correspond to various Zbtlink devices, including CPE2801, WE-series, WG-series, and Z8102AX-2DSIM models. It is important to note that the specific model number is more indicative than the brand label, as identical hardware and firmware can be rebranded and sold under different names. Therefore, the current list of affected models may not be exhaustive, and other rebranded or unbranded units could also be at risk.

What You Should Do

  • Identify Affected Devices: Prioritize identifying Zbtlink routers by their model number across all deployment locations, including remote offices, vehicle fleets, and contractor sites. Exercise extreme caution with any unknown cellular CPE devices.
  • Monitor for IoCs: Actively search for unbracketed kworker processes and the associated files listed in the Indicators of Compromise (IoCs) table below.
  • Block and Alert on C2 Traffic: Implement firewall rules to block and generate alerts for any outbound traffic on TCP ports 7000 and 7001 originating from network device segments, targeting the listed command-and-control domains and IP addresses.
  • Isolate or Replace: As no clean firmware is currently available, the most secure action is to replace affected devices, especially those handling critical traffic. If immediate replacement is not feasible, isolate these devices behind strict outbound controls and ensure their local network segment is completely separate from other sensitive networks.
  • Preserve Evidence: Before removing any compromised unit, collect and preserve logs, noting the model, firmware name, process states, and any relevant network events.
  • Avoid Simple Disabling: Do not rely solely on disabling the backdoor’s startup script. Firmware that shipped with a hidden remote-control function may harbor other undisclosed vulnerabilities. Replacing the equipment is a more secure long-term solution.

Indicators of Compromise (IoCs)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Type Indicator Description
Domain zbtctl.epplink[.]net Primary ENDLESSDOORS command-and-control domain
IP address 47.100.190[.]96 Resolution for zbtctl.epplink[.]net
IP address 47.107.224[.]89 Hardcoded command-and-control address
Domain online-string[.]com Secondary command-and-control domain
IP address 45.32.81[.]152 Resolution for online-string[.]com
Domain rbdg4nzqadui[.]wikaba[.]com Secondary command-and-control domain
IP address 43.248.136[.]125 Resolution for rbdg4nzqadui[.]wikaba[.]com
File path /usr/sbin/kworker ENDLESSDOORS implant binary
File path /usr/lib/librctl.so Related remote-control library
File path /etc/kworker.cfg Implant configuration file
File path /etc/init.d/skworker Startup script used to launch the implant
Network port TCP/7000 Implant check-in and command channel
Network port TCP/7001 Interactive shell connection
Command string rctlbash String that requests an interactive root shell
Firmware file / SHA-256 CPE2801_V22.10.09.bin / b3956cfbebf9c8d0b2c7a2ecbe59e71c31a5802f2084d25d93a984c0f811e2c7 Affected firmware image
Firmware file / SHA-256 WE1026-5G-WD_V21.04.07.bin / f961e4243e759453294340bc7d1b145016d70b97ab328caf47c64ea3cd818148 Affected firmware image
Firmware file / SHA-256 WE1326_V22.02.18_1.bin / 7791de11cd27cb596deff089904a6eab3a7e0aa391f867c2389582d5c78fef4c Affected firmware image
Firmware file / SHA-256 WE2007_V23.08.12.bin / 6926f919da7f4447229f49842266d884369e1587df655149673e46f1d8787e47 Affected firmware image
Firmware file / SHA-256 WE2008-DSIM_V23.08.11.bin / 09ed9ad3ac886f5aaf8357127b6dd5926bd4af1e2cc687a6a4856bcaedee2667 Affected firmware image
Firmware file / SHA-256 WE2416_V21.03.22_1.bin / 76a17581bbde4c0550e8f4abfd903923aceeb50dc69dae4dd904628c273b90ee Affected firmware image
Firmware file / SHA-256 WE2416_V21.03.22.bin / 76a17581bbde4c0550e8f4abfd903923aceeb50dc69dae4dd904628c273b90ee Affected firmware image
Firmware file / SHA-256 WE3326_V20.09.30.bin / f5a94e536a1cac8552fb9c327c4bac6017e034786be98cc402a149cb51250d8f Affected firmware image
Firmware file / SHA-256 WE826-T3-DSIM_V21.12.21.bin / b3e667235e9b41b8fc3594edaa64879750e7f75d7518fff7514d55837430411a Affected firmware image
Firmware file / SHA-256 WG108_V21.08.06_1.bin / 37efadf0f4a110be0145139a43ebd032abb5b27b79b1eb2ab3578dcd31655a9e Affected firmware image
Firmware file / SHA-256 WG1602_V23.10.11.bin / f019d03c2489b2bc486d71e355e07f8f2862dff078574a8662a5a45932e7e453 Affected firmware image
Firmware file / SHA-256 WG1608-DSIM_V23.03.16.bin / 73a0d95b8e23c7780cd91e978238c6db519665b05481fb228b4db9a9ec99c8ae Affected firmware image
Firmware file / SHA-256 WG209_V21.07.28.bin / efc8a8ead69c63ecfffd883cfbe6bd131082aa13c0d3b324c00d79f4c149bd92 Affected firmware image
Firmware file / SHA-256 WG2105_V22.05.30.bin / 1545169fa8a3ae182d8e39aca8ec6cb6849b864e38646f29017232813e397e77 Affected firmware image
Firmware file / SHA-256 WG259_V21.03.23.bin / b4fda77e082fbf961db02273999e92e715e1824140ea92b2ab30163338b6622b Affected firmware image
Firmware file / SHA-256 WG3526_V22.11.01.bin / 2d558bc9a6c7e7480e946f1c0524a651554887a1c563d7633f1903d06ff493fb Affected firmware image
Firmware file / SHA-256 Z8102AX-2DSIM-..._174431.bin / dcdaa1fe80707b8d8fde8ad36c3e62a53623aff09bf5ccc544d4c1a1a54208b8 Affected firmware image
Firmware file / SHA-256 ZBT-WE5927_V22.08.10.bin / 4f5d8319b4bad5d9243496c1358fda4783ea9a0865c32881b3f57ecedb879570 Affected firmware image
Firmware file / SHA-256 ZBT-WE5931AC_V22.05.31.bin / dee3908280b91cb7ad60c69c1d34c599ceed7c8c66c025851e5831482815b271 Affected firmware image
Firmware file / SHA-256 ZBT-WE5931_V22.05.31.bin / 47d8ffb3a9a3fe0337e3c1e355fab4847dd61952fbe9aad98aadede489ca31fd Affected firmware image
Firmware file / SHA-256 ZBT-WG2107_V22.09.08.bin / 71b20ebff0630b33c96bef320adc75901b34f1fd2cc9af974cf93ff37d102ec8 Affected firmware image
kworker SHA-256 dc1f4056af20677bdc7294ae4707f0c7bdfc85d8b57db212b622b9dc09c92731 Observed in CPE2801, WE3326, WE826-T3-DSIM, ZBT-WE5927, ZBT-WE5931AC and ZBT-WE5931
kworker SHA-256 33f8c0532100eeb10213d167e5eb483394a7e43bf6d276441a1573360622011a Observed in WE1026-5G-WD
kworker

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEPatchSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

OpenAI Expands GPT-3.5 Access With Unlimited Chats for All Users

Next Post

Critical npm Supply Chain Attack CHAINDROP Backdoors 400+ Packages

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenAI Expands GPT-3.5 Access With Unlimited Chats for All Users
August 7, 2026
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us