Security Researchers Uncover Multiple Backdoor Implants in Chinese-Made ZBT Routers

VulnCheck finds three distinct surveillance backdoors in firmware, affecting devices sold globally under various brand names

edit
By LineZotpaper
Published
Read Time2 min
Security researchers have discovered three different backdoor implants hidden in the firmware of routers manufactured by Chinese company Shenzhen Zhibotong Electronics (ZBT), warning that the devices, sold worldwide under multiple brand names, contain serious vulnerabilities that could allow remote attackers to take complete control.

The findings, published by security firm VulnCheck, detail a investigation that began with a Zbtlink AX3000 router. Researchers uncovered an implant they named ENDLESSDOORS, which automatically phones home to a command-and-control server and can execute arbitrary commands as root. The implant disguises itself as a normal Linux kernel process called kworker and starts automatically at boot. VulnCheck demonstrated the vulnerability by impersonating the command server and taking control of a test router, noting that if an attacker can hijack the connection to the implant's command server, they can obtain complete control of the device.

ENDLESSDOORS was found embedded in firmware for 20 ZBT models, including the Z8102AX, WG3526, and WE826-T3-DSIM, among others. The issue has been assigned CVE-2026-66747 with a CVSS score of 9.3.

Further investigation revealed two additional implants. In a separate purchase, VulnCheck bought an $88 Deep Orange cellular router from a US Amazon seller, which turned out to be a white-labeled ZBT-WE826-T2. Its older firmware contained implants dubbed DARKLANTERN and SPEAKINGSTONE.

DARKLANTERN operates as the infosrvd service, opening a listener on the WAN via UDP port 9992 and accepting commands directly from the Internet without authentication. An attacker only needs to send a fixed 19-byte info probe to extract identifying information such as model, firmware version, MAC address, and uptime. The implant's security mechanisms were found to be easily bypassed: its command payload checksum relies on a static, hardcoded salt ("mqonu.com"), and its internal MAC address filter can be circumvented by submitting a MAC field of all zeros.

§

Analysis

Why This Matters

  • These backdoors could allow attackers to remotely control millions of routers worldwide, potentially for surveillance, data theft, or as part of botnets.
  • The devices are sold under many brand names, making it difficult for consumers to know they are using a ZBT router and take appropriate action.
  • The vulnerabilities are actively exploitable, as demonstrated by researchers taking control of a test router.

Background

ZBT is a Chinese manufacturer based in Shenzhen that produces routers for OEM and ODM customers. Its hardware is sold globally under a wide array of brand names, often with little indication of the original manufacturer. The company's routers are commonly used in budget and mid-range networking products. Previous security research has identified vulnerabilities in similarly produced white-label networking equipment, but the discovery of three distinct backdoor implants in the firmware is particularly alarming.

Key Perspectives

VulnCheck (Security Researchers): They have identified and disclosed three separate backdoor mechanisms, assigned a high severity CVE score, and demonstrated practical exploitation. Their work highlights a systemic security failure in the supply chain. ZBT (Manufacturer): The company has not publicly responded to the findings. The presence of multiple intentional backdoors suggests either a deliberate surveillance capability or extremely poor security practices in firmware development. Consumers and Businesses: Users of these routers face a serious security risk. Without firmware updates or manufacturer action, affected devices remain vulnerable indefinitely. The lack of clear branding makes identifying and replacing such devices difficult.

What to Watch

  • Whether ZBT issues a firmware update or recall for affected devices.
  • Potential response from Amazon and other retailers regarding the sale of these routers.
  • Further research into the scope of affected devices and whether the backdoors are linked to state-sponsored activity.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.