Chinese-made Zbtlink routers have a backdoor, researchers say
At least 100,000 of the routers are deployed worldwide.

Image by Cybernews.
- Researchers say more than 20 Zbtlink and Wiflyer router models ship with a hidden backdoor enabling remote network access.
- VulnCheck estimates at least 100,000 affected routers are deployed worldwide in homes, small businesses, and office environments.
- The backdoor reportedly contacts a Chinese-registered domain and specific IP address every 35 seconds without user awareness.
- Security experts warn compromised routers could provide access to other devices on the same network for intrusion or espionage.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
More than 20 models of a Chinese-made router, available throughout the world, ship with a backdoor that could allow access to and potential connections to other devices on the network, researchers with cybersecurity firm VulnCheck said on Wednesday.
The finding adds to growing Western concerns about cybersecurity risks posed by Chinese-made networking equipment. Western governments have warned for years about hackers exploiting such devices, and US regulators moved this year to restrict imports of foreign-made routers.
The previously unreported backdoor, dubbed "Endlessdoors" by the researchers who discovered it, ships in multiple router models manufactured and sold by Zbtlink around the world under both the Zbtlink and Wiflyer brand names, according to Jacob Baines, the chief technology officer at VulnCheck, who found the backdoor.
Zbtlink has not yet responded to a request for comment.
Baines estimates that at least 100,000 such routers are deployed worldwide, although he said it’s not possible to say exactly where, or how many are active in the US.
Western governments have warned about Chinese-linked hackers abusing small office and home office routers and other internet-connected devices to gain access to networks for later intrusions, as well as cyberespionage. Beijing regularly denies condoning or carrying out cyberattacks or cyberespionage.
In March, the Federal Communications Commission announced it would ban the import of new foreign-made consumer routers over national security concerns, though the agency subsequently exempted many non-Chinese firms.
In February, the state of Texas sued TP-Link, a California-based router manufacturer spun off from a Chinese firm, alleging that the company allowed Beijing access to American consumers’ devices, a claim the company disputed.
Strong password generator
The backdoor discovered by Baines automatically communicates to a specific IP address and a Chinese-registered domain every 35 seconds, he said in a blog post on the company’s website. Whoever controls those domains could take control of the router and potentially use it to access other devices on the same network, he said.
Baines said most people who order this router and use it for their small business or home office would likely have no clue that it could allow this sort of access.
"If I have it in my lab, in my lab at my university, you just invited them straight into your lab, and they can roam the network as they choose," he said.
"The capabilities are devastating."
Reuters could not determine why the backdoor exists, what purpose it serves, or whether it has ever been abused.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.