Security
Chinese router manufacturer Zbtlink Electronics said Thursday it is halting sales of routers found to contain a backdoor and removing the affected software from its website while it works on fixes to address the issue.
The vulnerability was uncovered by cybersecurity firm VulnCheck, which identified the backdoor in at least 20 router models made by Shenzhen-based Zbtlink, Reuters reported. In a statement posted to its website, Zbtlink acknowledged the research, which found that the flaw could allow attackers to access and control affected devices — and potentially other devices connected to the same network.
VulnCheck CTO Jacob Baines discovered the backdoor and named it "Endlessdoors." Zbtlink described the tool as intended solely for after-sales technical support, saying it was designed to help customers with device troubleshooting and configuration, and only meant to be used with a customer's explicit request and authorization. The company said the tool has never been used to gain unauthorized access to devices.
The disclosure comes as Western governments grow increasingly wary of cybersecurity risks tied to Chinese-made networking hardware. Canada's government issued a security advisory Wednesday specifically addressing the vulnerability in the affected routers.
According to Baines' technical analysis, the backdoor automatically connected to a specific IP address and a Chinese-registered domain every 35 seconds. Anyone who controlled — or managed to hijack — those domains could potentially seize control of an affected router and use it as an entry point to reach other devices on the same network.
According to the report, Bains told that routers deployed worldwide remain vulnerable to hostile takeover through the backdoor. He said the only real mitigation available to users is to disconnect the affected routers from their networks entirely and watch for signs that a device may have already been compromised.
Baines also pushed back on Zbtlink's explanation, noting that it doesn't account for why the tool was given a name deliberately difficult to identify unless someone already knew to look for it — or why the company implemented the feature in a way that left it exposed to hijacking in the first place.
The vulnerability was uncovered by cybersecurity firm VulnCheck, which identified the backdoor in at least 20 router models made by Shenzhen-based Zbtlink, Reuters reported. In a statement posted to its website, Zbtlink acknowledged the research, which found that the flaw could allow attackers to access and control affected devices — and potentially other devices connected to the same network.
VulnCheck CTO Jacob Baines discovered the backdoor and named it "Endlessdoors." Zbtlink described the tool as intended solely for after-sales technical support, saying it was designed to help customers with device troubleshooting and configuration, and only meant to be used with a customer's explicit request and authorization. The company said the tool has never been used to gain unauthorized access to devices.
The disclosure comes as Western governments grow increasingly wary of cybersecurity risks tied to Chinese-made networking hardware. Canada's government issued a security advisory Wednesday specifically addressing the vulnerability in the affected routers.
According to Baines' technical analysis, the backdoor automatically connected to a specific IP address and a Chinese-registered domain every 35 seconds. Anyone who controlled — or managed to hijack — those domains could potentially seize control of an affected router and use it as an entry point to reach other devices on the same network.
According to the report, Bains told that routers deployed worldwide remain vulnerable to hostile takeover through the backdoor. He said the only real mitigation available to users is to disconnect the affected routers from their networks entirely and watch for signs that a device may have already been compromised.
Baines also pushed back on Zbtlink's explanation, noting that it doesn't account for why the tool was given a name deliberately difficult to identify unless someone already knew to look for it — or why the company implemented the feature in a way that left it exposed to hijacking in the first place.
See What’s Next in Tech With the Fast Forward Newsletter
START - UP
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




