Chinese maker suspends sales of 20+ models after researchers find factory-shipped implant that phones home every 35 seconds.
Shenzhen-based Zbtlink Electronics suspended sales of multiple router models on Thursday and yanked affected firmware from its site. The move followed a VulnCheck report that more than 20 models ship with a hidden backdoor dubbed Endlessdoors.
The implant runs as root from boot. It connects automatically to Chinese-registered domains and IP addresses every 35 seconds. No user action or misconfiguration is needed. Whoever controls those endpoints can issue shell commands or open a full reverse root shell on the device and reach other machines on the same network.
How the Backdoor Works
VulnCheck CTO Jacob Baines found the code while examining a Zbtlink AX3000 Dual SIM 5G CPE bought on Alibaba. Processes named “kworker” hide in plain sight. They are actually a customized version of an obscure 2015 GitHub tool called rctl. The client sends a simple MAC-address registration with no authentication or encryption. The server can then run any command as root.
Baines and his team demonstrated the takeover in their lab. They simply answered the outbound call and received an interactive root shell. The same implant appears in every firmware image previously listed on Zbtlink’s download page.
Affected models include CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and Z8102AX-2DSIM. Devices are sold under the Zbtlink and Wiflyer brands and often rebranded for other companies through OEM and ODM deals. Baines estimates at least 100,000 units are already deployed worldwide.
Company Response and Official Reaction
Zbtlink called the feature “solely an after-sales technical support tool” meant for troubleshooting “only upon explicit request and authorization.” The company said it has never been used for unauthorized access and claimed it is normally limited to sample units. Yet the firmware on its public download page contained the implant across two dozen images. After the report, the firm posted a notice that it had detected security vulnerabilities, temporarily removed the files, and was developing patched versions. It also suspended sales of the affected routers.
Read the full response here: https://www.zbtlink.com/pages/zbt-router-firmware-download-announcement
The Canadian Centre for Cyber Security issued an advisory on August 5 listing the specific firmware versions and urging users to apply updates when available. The disclosure lands amid broader Western scrutiny of Chinese-made networking gear.
Baines told Reuters that routers already in the field remain vulnerable. “The only mitigation for router users is to remove them from their networks and monitor for any signs of compromise.” He noted that the company’s explanation does not address the deliberate naming that hides the process or the complete lack of authentication.
Why This Matters
Most buyers of these low-cost 4G/5G CPE and Wi-Fi 6 routers—small businesses, home offices, hotels, vehicles—have no reason to inspect process lists or outbound traffic. The implant dials out, so typical firewalls and NAT offer no protection. Once an attacker answers the call, the local network is open.
Defenders should inventory devices by exact model number rather than brand, block the known C2 endpoints, watch for outbound traffic on ports 7000 and 7001, and treat any remaining units as untrusted. Replacement is the safest long-term step.
