Zbtlink router firmware unauthenticated root-shell backdoor ENDLESSDOORS security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A factory-shipped backdoor in Zbtlink router firmware exposes at least 20 router models to unauthenticated root shell access. The implant, named ENDLESSDOORS, is present in firmware images spanning more than 2 years and can let a remote operator take over affected routers. Zbtlink has pulled impacted downloads and is developing patched firmware, while defenders are told to look for the implant's files and block its C2 traffic.
Related Happenings
D-Link DSL gateway routers command injection (CVE-2026-0625, actively exploited)
Vulnerability
H score34
First: 06.01.2026 21:52
Last: 06.01.2026 21:52
Sources 1
About this happening:
CVE-2026-0625 is an unauthenticated command injection flaw affecting legacy D-Link DSL gateway routers, creating remote code execution risk for exposed management...
D-Link DSL gateway routers command injection (CVE-2026-0625, actively exploited)
VulnerabilityAbout this happening: CVE-2026-0625 is an unauthenticated command injection flaw affecting legacy D-Link DSL gateway routers, creating remote code execution risk for exposed management...
Latest development: 08.01.2026 11:13
Cisco patched CVE-2026-20029 in Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) after public proof-of-concept exploit code appeared. The XML parsing flaw in the web-based management interface can let an attacker with valid administrative credentials upload a malicious file and read arbitrary files from the underlying operating system on unpatched devices, including sensitive data.
Timeline
-
06.08.2026 11:05 2 articles · 3h ago
VulnCheck discloses ENDLESSDOORS backdoor in Zbtlink router firmware
Initial DisclosureVulnCheck disclosed a factory-shipped backdoor called ENDLESSDOORS in at least 20 Zbtlink router models and 21 firmware images spanning more than 2 years. The implant is a customized rctl (remote control linux) component that starts at boot through the init.d script skworker, masquerades as a kworker process, beacons to C2 infrastructure, can execute root commands or spawn a live interactive root shell, and can be controlled by anyone who hijacks the outbound rctl traffic or the DNS resolution for rbdg4nzqadui[.]wikaba[.]com. Zbtlink temporarily removed impacted firmware downloads and said it is working on secured patched firmware.
Show sources
- Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells — thehackernews.com — 06.08.2026 11:05
- Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells — thehackernews.com — 06.08.2026 11:05