Zbtlink Halts Firmware Downloads Amid Backdoor Allegations
A cybersecurity firm has accused Chinese router manufacturer Zbtlink of shipping devices with pre-installed 'backdoors' that allow remote command execution.

Zbtlink, a prominent Chinese router manufacturer, has suspended firmware downloads from its website. This action follows an in-depth report by Jacob Baines, CTO of cybersecurity company VulnCheck, which claims Zbtlink devices contain embedded backdoors.
Baines's research indicates that a Zbtlink device continuously attempts to establish communication with a command-and-control server on the internet. He characterized this behavior not as a result of a hack, but rather as an inherent feature of the devices as shipped by the manufacturer.
The vulnerability, which Baines named “ENDLESSDOORS,” was reportedly uploaded to GitHub in early 2015 and has remained unaddressed since. This protocol allows for the transmission of individual shell commands or the initiation of a reverse bash shell, providing extensive control over the device.
Baines further elaborated that the communication protocol’s vocabulary consists of two primary commands: “run this as root” and “give me a root shell.” This design implies that any entity along the communication path could potentially hijack the client/server interaction, a scenario that VulnCheck researchers claim to have successfully demonstrated.
According to Baines, every firmware image available on Zbtlink's download page, estimated at approximately two dozen, was susceptible to this form of hijacking. He noted that VulnCheck did not engage in a responsible disclosure process, asserting that the intentional nature of the functionality rendered such an approach inappropriate.
In response to these allegations, Zbtlink informed The Register that VulnCheck had misrepresented the code. The company stated that the feature was solely for after-sales maintenance purposes and was intended to be present only on sample units for customer software debugging, not on mass-produced shipments.
However, The Register questioned the credibility of Zbtlink's explanation, noting that the company subsequently posted a warning on its download page. The warning stated that security vulnerabilities had been detected in selected router firmware releases and, as a precaution, the affected versions had been temporarily removed, with engineering teams actively developing patched firmware.
This warning was reportedly published within the past week. Baines provided several recommendations for mitigating the risk, ultimately advising that for any network handling critical traffic, devices should be replaced or, at minimum, placed behind stringent egress controls and their local area network (LAN) treated as untrusted.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



