AUTO-UPDATED

Biggest backdoor yet found in Chinese routers sold under multiple brand names

Cybersecurity researchers at VulnCheck have discovered a critical, deliberate backdoor named ENDLESSDOORS embedded in various routers manufactured by Shenzhen Zhibotong Electronics, posing significant risks to global network security.

Key Points

  • The ENDLESSDOORS backdoor uses a tool called rctl to establish outbound connections to command servers, bypassing firewalls and standard network security measures.
  • Affected devices are sold under multiple brand names, including Zbtlink and Wiflyer, often obscuring their true origin from consumers and internet service providers.
  • The vulnerability allows remote attackers to execute arbitrary shell commands or spawn reverse bash shells on compromised hardware.
  • VulnCheck identified 20 specific model numbers, such as the WE826-T3-DSIM and Z8102AX-2DSIM, that contain this security flaw.
  • Experts recommend that users immediately disconnect and replace any hardware matching the identified model list to prevent unauthorized network access.

Why it Matters

This discovery highlights the severe supply chain risks associated with rebadged networking hardware that may contain pre-installed malicious firmware. Because these devices initiate outbound connections, they can bypass traditional perimeter defenses, leaving both home and enterprise networks vulnerable to persistent remote control.
9to5Mac Published by Ben Lovejoy
Read original