Zbtlink Chinese Router Sold Worldwide Contains a Hidden Backdoor Affecting 20+ Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love
Zbtlink routers sold in global markets have been found carrying a hidden remote-control implant that starts with the device.

The discovery affects equipment used in homes, offices, temporary sites and vehicles, turning a trusted network gateway into a potential entry point.

The affected devices may be present anywhere small, low-cost network hardware is deployed today.

The implant, called ENDLESSDOORS, does not rely on a victim clicking a link or an attacker breaking into a router.

It calls out from the router to external infrastructure and waits for instructions, meaning ordinary firewall rules may not stop the connection.

Analysts at VulnCheck identified the code inside firmware images for more than 20 Zbtlink models and assigned the issue CVE-2026-66747. 

VulnCheck said in a report shared with Cyber Security News (CSN) that the component launches at boot and can run commands with full administrative control.

The finding matters because routers sit between users and the internet. A hostile operator could use that position to inspect traffic, move deeper into a local network, change settings, or install further tools.

Earlier reporting on persistent SOHO device footholds shows why compromised edge devices can remain valuable to attackers for long periods.

The hidden component disguises itself as kworker, a name normally associated with routine Linux activity.

On affected routers, the suspicious process is not a normal system thread: it runs as root, has its own memory use, and connects outward as a customized version of the old remote-control utility rctl.

The connection is especially dangerous because it has no meaningful identity check. After reaching its server, the implant sends a short registration message containing a label and the router’s LAN MAC address.

The server can then pass commands that the device executes as root, or request an interactive shell.

Unlike a software vulnerability that needs a carefully prepared request, the operator only needs to control or intercept the destination the router already trusts.

zbtctl.epplink[.]net endpoint which currently resolves to 47.100.190[.]96, hosted in Alibaba Cloud (Source – VunCheck)

The report says anyone able to alter the domain’s resolution can take over an implant trying to connect. No user action is required.

This outbound design changes the attack path. The router does not need to expose a management port to the public internet, and it can still reach command infrastructure through NAT and common outbound filtering.

That risk lands as router scanning reaches record highs, making outbound monitoring as important as guarding web administration panels.

Researchers confirmed the implant across 21 firmware images covering CPE2801, WE-series, WG-series and Z8102AX-2DSIM devices.

Model number matters more than the badge because the same hardware and firmware can be sold under different labels. The known list may not represent every rebranded or unbranded unit in circulation.

What Owners Should Do Now

There is no confirmed clean firmware for the affected products, so this is not a normal update-and-move-on problem.

Organizations should identify routers by model number, including devices installed at branch sites, hotels, vehicle fleets, or by contractors, and treat unknown cellular CPE with extra care.

Administrators who can access a device should look for unbracketed kworker processes and the related files listed in the indicators below.

They should also block and alert on the listed destinations, while watching for outbound traffic on TCP ports 7000 and 7001 from network-device segments.

Blocking alone is not a complete answer because the affected firmware itself cannot be trusted.

VulnCheck recommends replacing devices that carry real traffic; where replacement cannot happen immediately, isolate them behind strict outbound controls and keep their local network separate.

This cautious approach also reflects network appliance backdoor risks seen when attackers gain durable control of infrastructure.

Security teams should preserve logs and record the model, firmware name, process state, and relevant network events before removing a unit.

Replacing affected equipment is safer than simply disabling its startup script, since an image that shipped with a hidden remote-control function may contain other unknown weaknesses.

The urgency is reinforced by unpatched router attack exposure, where unsupported network devices remain easy targets.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain zbtctl.epplink[.]net Primary ENDLESSDOORS command-and-control domain
IP address 47.100.190[.]96 Resolution for zbtctl.epplink[.]net
IP address 47.107.224[.]89 Hardcoded command-and-control address
Domain online-string[.]com Secondary command-and-control domain
IP address 45.32.81[.]152 Resolution for online-string[.]com
Domain rbdg4nzqadui[.]wikaba[.]com Secondary command-and-control domain
IP address 43.248.136[.]125 Resolution for rbdg4nzqadui[.]wikaba[.]com
File path /usr/sbin/kworker ENDLESSDOORS implant binary
File path /usr/lib/librctl.so Related remote-control library
File path /etc/kworker.cfg Implant configuration file
File path /etc/init.d/skworker Startup script used to launch the implant
Network port TCP/7000 Implant check-in and command channel
Network port TCP/7001 Interactive shell connection
Command string rctlbash String that requests an interactive root shell
Firmware file / SHA-256 CPE2801_V22.10.09.bin / b3956cfbebf9c8d0b2c7a2ecbe59e71c31a5802f2084d25d93a984c0f811e2c7 Affected firmware image
Firmware file / SHA-256 WE1026-5G-WD_V21.04.07.bin / f961e4243e759453294340bc7d1b145016d70b97ab328caf47c64ea3cd818148 Affected firmware image
Firmware file / SHA-256 WE1326_V22.02.18_1.bin / 7791de11cd27cb596deff089904a6eab3a7e0aa391f867c2389582d5c78fef4c Affected firmware image
Firmware file / SHA-256 WE2007_V23.08.12.bin / 6926f919da7f4447229f49842266d884369e1587df655149673e46f1d8787e47 Affected firmware image
Firmware file / SHA-256 WE2008-DSIM_V23.08.11.bin / 09ed9ad3ac886f5aaf8357127b6dd5926bd4af1e2cc687a6a4856bcaedee2667 Affected firmware image
Firmware file / SHA-256 WE2416_V21.03.22_1.bin / 76a17581bbde4c0550e8f4abfd903923aceeb50dc69dae4dd904628c273b90ee Affected firmware image
Firmware file / SHA-256 WE2416_V21.03.22.bin / 76a17581bbde4c0550e8f4abfd903923aceeb50dc69dae4dd904628c273b90ee Affected firmware image
Firmware file / SHA-256 WE3326_V20.09.30.bin / f5a94e536a1cac8552fb9c327c4bac6017e034786be98cc402a149cb51250d8f Affected firmware image
Firmware file / SHA-256 WE826-T3-DSIM_V21.12.21.bin / b3e667235e9b41b8fc3594edaa64879750e7f75d7518fff7514d55837430411a Affected firmware image
Firmware file / SHA-256 WG108_V21.08.06_1.bin / 37efadf0f4a110be0145139a43ebd032abb5b27b79b1eb2ab3578dcd31655a9e Affected firmware image
Firmware file / SHA-256 WG1602_V23.10.11.bin / f019d03c2489b2bc486d71e355e07f8f2862dff078574a8662a5a45932e7e453 Affected firmware image
Firmware file / SHA-256 WG1608-DSIM_V23.03.16.bin / 73a0d95b8e23c7780cd91e978238c6db519665b05481fb228b4db9a9ec99c8ae Affected firmware image
Firmware file / SHA-256 WG209_V21.07.28.bin / efc8a8ead69c63ecfffd883cfbe6bd131082aa13c0d3b324c00d79f4c149bd92 Affected firmware image
Firmware file / SHA-256 WG2105_V22.05.30.bin / 1545169fa8a3ae182d8e39aca8ec6cb6849b864e38646f29017232813e397e77 Affected firmware image
Firmware file / SHA-256 WG259_V21.03.23.bin / b4fda77e082fbf961db02273999e92e715e1824140ea92b2ab30163338b6622b Affected firmware image
Firmware file / SHA-256 WG3526_V22.11.01.bin / 2d558bc9a6c7e7480e946f1c0524a651554887a1c563d7633f1903d06ff493fb Affected firmware image
Firmware file / SHA-256 Z8102AX-2DSIM-..._174431.bin / dcdaa1fe80707b8d8fde8ad36c3e62a53623aff09bf5ccc544d4c1a1a54208b8 Affected firmware image
Firmware file / SHA-256 ZBT-WE5927_V22.08.10.bin / 4f5d8319b4bad5d9243496c1358fda4783ea9a0865c32881b3f57ecedb879570 Affected firmware image
Firmware file / SHA-256 ZBT-WE5931AC_V22.05.31.bin / dee3908280b91cb7ad60c69c1d34c599ceed7c8c66c025851e5831482815b271 Affected firmware image
Firmware file / SHA-256 ZBT-WE5931_V22.05.31.bin / 47d8ffb3a9a3fe0337e3c1e355fab4847dd61952fbe9aad98aadede489ca31fd Affected firmware image
Firmware file / SHA-256 ZBT-WG2107_V22.09.08.bin / 71b20ebff0630b33c96bef320adc75901b34f1fd2cc9af974cf93ff37d102ec8 Affected firmware image
kworker SHA-256 dc1f4056af20677bdc7294ae4707f0c7bdfc85d8b57db212b622b9dc09c92731 Observed in CPE2801, WE3326, WE826-T3-DSIM, ZBT-WE5927, ZBT-WE5931AC and ZBT-WE5931
kworker SHA-256 33f8c0532100eeb10213d167e5eb483394a7e43bf6d276441a1573360622011a Observed in WE1026-5G-WD
kworker SHA-256 00a1228648fffa7338076970037b89f679a166a08c4d9573f1f27973ec6ed497 Observed in WE1326, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG259, WG3526 and ZBT-WG2107
kworker SHA-256 e85104fce4061d52d47f4528df9aaf656edc49f05c0f026c5bc6b65d57eb7f22 Observed in WE2007 and WE2008-DSIM
kworker SHA-256 ab8467e1495479693f4de8e838a5aeb61a65f3682d68f5b2d7c856cbfc91a247 Observed in WE2416 firmware images
kworker SHA-256 31ee58a134b766f6ed4424a22cc2cb08cfabbc9a5f35e0ae11a250c81ccc7f5e Observed in Z8102AX-2DSIM

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world