Cybersecurity researchers at VulnCheck have discovered a critical, deliberate backdoor named ENDLESSDOORS embedded in various routers manufactured by Shenzhen Zhibotong Electronics, posing significant risks to global network security.
Key Points
- The ENDLESSDOORS backdoor uses a tool called rctl to establish outbound connections to command servers, bypassing firewalls and standard network security measures.
- Affected devices are sold under multiple brand names, including Zbtlink and Wiflyer, often obscuring their true origin from consumers and internet service providers.
- The vulnerability allows remote attackers to execute arbitrary shell commands or spawn reverse bash shells on compromised hardware.
- VulnCheck identified 20 specific model numbers, such as the WE826-T3-DSIM and Z8102AX-2DSIM, that contain this security flaw.
- Experts recommend that users immediately disconnect and replace any hardware matching the identified model list to prevent unauthorized network access.