Router vendor pulls firmware after ENDLESSDOORS backdoor claims

VulnCheck found a phone-home implant in Zbtlink router firmware while the vendor called it a maintenance feature.

CSBadmin
2 Min Read

Chinese Wi-Fi router maker Zbtlink has paused firmware downloads after researchers disclosed what they call a factory-shipped backdoor in at least 20 router models.

VulnCheck chief technology officer Jacob Baines said the implant, named ENDLESSDOORS, appears in all 21 firmware images the vendor currently offers, spanning more than two years of releases. The code starts automatically and beacons to Chinese command-and-control infrastructure as often as every 35 seconds.

ENDLESSDOORS is built on rctl, a remote control tool uploaded to GitHub in 2015 that implements a simple C2 client and server. The implant masquerades as a Linux kernel thread but is a root-level userland process that blends in with legitimate kworker processes. Baines said the tool sends a fixed 39-byte hello with no handshake or verification, meaning anyone controlling the target server can hijack every implant that phones home.

Zbtlink denies the finding, telling The Register the code is an after-sales maintenance feature kept only on sample units and excluded from mass production. But the company’s download page now carries an update saying firmware security vulnerabilities were detected and impacted releases were temporarily taken down.

Baines’ advice to owners is blunt: the devices phone home waiting for orders, not because they were hacked, but because they shipped that way. Users should assume any exposed Zbtlink device is remotely controllable and check for the implant.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.