{"id":2236,"date":"2026-08-06T09:17:28","date_gmt":"2026-08-06T09:17:28","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2236"},"modified":"2026-08-06T09:17:28","modified_gmt":"2026-08-06T09:17:28","slug":"chinese-made-zbtlink-routers-ship-with-backdoor-that-opens-unauthenticated-root-shells","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2236","title":{"rendered":"Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 06, 2026<\/span><\/span><span class=\"p-tags\">IoT Security \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg3VqhMa79pNymspvzHhSpHG4HCDAGn4nAD-7ZwQgDuSOELhM0xxHASqfnd2ThEv8XJ0tM58bPsGPHcobfoaEEWW4Am9H-Wd9bpb-QqYRQfFcFKrvbLjwEGYu0VfIAclBcVn9PpMWS02ZAtOa7hhwg8e45cYcgYYX0C1_yQptZh7-ZvqFHpf-9uqq5csbCj\/s1700-e365\/router-hacking.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a \u00abfactory-shipped backdoor\u00bb implanted in at least 20 Chinese router models from Zbtlink.<\/p>\n<p>According to a <a href=\"https:\/\/www.vulncheck.com\/blog\/zbt-endlessdoors\" target=\"_blank\">new report<\/a> from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds.<\/p>\n<p>They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. The \u00abphone home\u00bb implants have been codenamed <strong>ENDLESSDOORS<\/strong>.<\/p>\n<p>\u00abENDLESSDOORS, at its core, is a small tool called <a href=\"https:\/\/github.com\/ycsunjane\/rctl\" target=\"_blank\">rctl<\/a> (remote control linux),\u00bb Jacob Baines, VulnCheck Chief Technology Officer, said. \u00abUploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server.\u00bb<\/p>\n<p>\u00abThe server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The \u00abkworker\u00bb worker process running on Zbtlink AX3000, which VulnCheck analyzed, is a customized version of rctl that&#8217;s configured to contact the following &#8211;<\/p>\n<p><a name=\"more\"\/><\/p>\n<ul>\n<li>47.107.224[.]89<\/li>\n<li>rbdg4nzqadui[.]wikaba[.]com<\/li>\n<\/ul>\n<p>What&#8217;s more, there is no handshake, negotiation, or authentication involved. Once the implant sends a \u00abhello\u00bb message to the server alongside the LAN MAC address, it&#8217;s engineered to run whatever the server sends back in response.<\/p>\n<p>\u00abOne reserved string, rctlbash, tells the implant to open a second connection to port 7001, allocate a pseudo-terminal, spawn \/bin\/sh, and bridge it,\u00bb Baines explained. \u00abThat is a live interactive root shell.\u00bb<\/p>\n<p>\u00abThe vocabulary of this protocol is two phrases: run this as root, and give me a root shell. Anyone along the network path can hijack the client\/server communication. Anyone who controls the resolution of rbdg4nzqadui.wikaba[.]com, or the address it resolves to, can control any ENDLESSDOORS implant that tries to phone home.\u00bb<\/p>\n<p>An attacker can take advantage of this loophole to hijack the outbound rctl communications and obtain a live root shell, and take over control of the router without having to be reachable from the internet.<\/p>\n<p>VulnCheck noted that every firmware listed on zbtlink.com&#8217;s download page embeds the rctl implant and starts it at boot with an init.d script named \u00abskworker.\u00bb The list of affected models is below &#8211;<\/p>\n<ul>\n<li>CPE2801<\/li>\n<li>WE1026-5G-WD<\/li>\n<li>WE1326<\/li>\n<li>WE2007<\/li>\n<li>WE2008-DSIM<\/li>\n<li>WE2416<\/li>\n<li>WE3326<\/li>\n<li>WE5927<\/li>\n<li>WE5931<\/li>\n<li>WE5931AC<\/li>\n<li>WE826-T3-DSIM<\/li>\n<li>WG108<\/li>\n<li>WG1602<\/li>\n<li>WG1608-DSIM<\/li>\n<li>WG209<\/li>\n<li>WG2105<\/li>\n<li>WG2107<\/li>\n<li>WG259<\/li>\n<li>WG3526<\/li>\n<li>Z8102AX-2DSIM<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Each of these models have been found to have been found to dial the same set of four primary and secondary endpoints &#8211;<\/p>\n<ul>\n<li>zbtctl.epplink[.]net (47.100.190[.]96)<\/li>\n<li>47.107.224[.]89<\/li>\n<li>online-string[.]com (45.32.81[.]152)<\/li>\n<li>rbdg4nzqadui.wikaba[.]com (43.248.136[.]125)<\/li>\n<\/ul>\n<p>As of writing, users <a href=\"https:\/\/www.zbtlink.com\/pages\/zbt-router-firmware-download\" target=\"_blank\">visiting the firmware downloads<\/a> page on Zbtlink&#8217;s website are displayed the below message &#8211;<\/p>\n<p><em>We have detected firmware security vulnerabilities affecting selected router firmware releases.<\/em><\/p>\n<p><em>As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. Our engineering team is working intensively to develop and validate secured patched firmware.<\/em><\/p>\n<p><em>We will notify you immediately once the fixed, security-validated firmware is available for release.<\/em><\/p>\n<p><em>We apologize for the inconvenience caused. Thank you for your understanding.<\/em><\/p>\n<p>The Hacker News has contacted the Chinese router manufacturer for further comment, and we will update the story if we hear back.<\/p>\n<p>In the meantime, customers are advised to check the process list, scan the file system for files like \/usr\/sbin\/kworker, \/usr\/lib\/librctl.so, \/etc\/kworker.cfg, and \/etc\/init.d\/skworker, and block the egress points.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 06, 2026IoT Security \/ Malware Cybersecurity researchers have disclosed details of a \u00abfactory-shipped backdoor\u00bb implanted in at least 20 Chinese router models from Zbtlink. According to a new&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2237,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[179,2908,2911,61,873,214,2910,725,2909],"class_list":["post-2236","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoor","tag-chinesemade","tag-opens","tag-root","tag-routers","tag-shells","tag-ship","tag-unauthenticated","tag-zbtlink"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2236","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2236"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2236\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2237"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2236"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}