Summary
- Zbtlink has suspended sales of affected routers and removed software from its website while developing updates following the Endlessdoors disclosure.
- VulnCheck says the embedded mechanism runs with root privileges and uses an outbound control channel without authentication or transport encryption.
- Zbtlink says the component was an authorised after-sales support tool and has never been used for unauthorised access, leaving intent disputed while the implementation weakness is addressed.
Chinese router manufacturer Zbtlink Electronics has suspended sales of affected routers and pulled software from its website after researchers disclosed a remote-control mechanism embedded in firmware across at least 20 models.
The manufacturer’s response materially advances the security finding Cyber Insider covered on 6 August. At that stage, research from VulnCheck had established the presence and capability of the mechanism, but Zbtlink’s explanation and remediation plans had not yet been published.
Zbtlink now says it is developing updates. The company disputes the characterisation of the component as a malicious backdoor, describing it as an after-sales technical support tool intended to help customers with troubleshooting and configuration only after an explicit request and authorisation.
The company also says the mechanism has never been used for unauthorised access.
Those statements address claimed purpose, but not the technical weakness described by VulnCheck. The security company named the mechanism Endlessdoors and identified it in firmware covering at least 20 Zbtlink router models.
VulnCheck’s analysis says the component starts automatically, runs with root privileges, and repeatedly establishes outbound connections to hard-coded control infrastructure. Its control channel lacks authentication and transport encryption.
According to VulnCheck, an attacker able to answer the router’s outbound connection — including through control or hijacking of the relevant infrastructure — can obtain a root shell on the device. The researchers demonstrated that behaviour in an isolated laboratory environment.
That makes intended use only part of the security question. A privileged remote-support mechanism can still expose customers if its design does not establish which party is authorised to issue commands or protect the traffic carrying those commands.
Reuters reported that Zbtlink has stopped sales of affected routers and is removing the affected software from its website while updates are developed. The response acknowledges a need for technical remediation even as the manufacturer disputes the implication that the capability was designed for covert or unauthorised access.
VulnCheck also found that the mechanism was present across firmware images for 20 models sold under Zbtlink and related branding. The company provides original equipment and design manufacturing services, which creates the possibility that substantially similar hardware or firmware may appear under other brands. VulnCheck said it could not enumerate the full affected population.
The Canadian government has issued a security advisory relating to the routers, adding a public-sector hardware-assurance dimension to the disclosure. Reuters also reported that the products are deployed internationally, although precise geographic distribution is not established.
The case is best treated as a product-security and supply-chain problem rather than evidence of state activity. A remotely accessible support function is not, by itself, proof of espionage or malicious intent. Conversely, a support purpose does not make an unauthenticated root-level control channel safe.
The accountability lies partly in implementation. Administrative mechanisms embedded beneath the ordinary router interface can outlive support interactions, remain difficult for customers to inspect, and provide privileged access that is not represented by the normal login or management model.
There is no confirmed evidence in the reviewed sources that Endlessdoors has been used in malicious attacks against deployed routers. Zbtlink and VulnCheck therefore agree on the existence of the functionality while differing on how its purpose should be characterised.
The next test is remediation. Sales and software have been suspended while Zbtlink develops updates, but affected devices already in use remain the more difficult part of the response. Until updated firmware and its deployment path can be assessed, the issue remains both a router-security problem and a wider question about hidden administrative capabilities in network hardware.


