Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zbtlink Routers Expose Security Flaw with Built-in Backdoor

Zbtlink Routers Expose Security Flaw with Built-in Backdoor

Posted on August 6, 2026 By CWS

Recent findings by cybersecurity experts reveal a significant security vulnerability in at least 20 models of routers manufactured by Zbtlink. These devices reportedly come with a pre-installed backdoor, compromising their security integrity. The analysis by VulnCheck highlights that this backdoor exists in all of the 21 available firmware images from Zbtlink, which date back over two years.

Details of the Security Vulnerability

The embedded backdoors operate automatically, attempting to connect with command-and-control (C2) servers in China every 35 seconds. Although they appear as Linux kernel threads, they are actually userland processes with root access, blending in with legitimate processes. The backdoor, named ENDLESSDOORS, is essentially a remote control tool, rctl, which was uploaded to GitHub in 2015 and hasn’t been updated since.

According to Jacob Baines, VulnCheck’s CTO, this tool enables a server to send commands to the router, including the ability to initiate a reverse bash shell. This communication occurs without any authentication, allowing anyone intercepting the traffic to gain control over the device.

Technical Analysis and Risks

The customized rctl version in the Zbtlink AX3000 model analyzed by VulnCheck is configured to communicate with specific endpoints, including 47.107.224.89 and rbdg4nzqadui.wikaba.com. The lack of authentication means an attacker could easily hijack the communication, gaining a live root shell and control over the router remotely, without needing direct internet access.

VulnCheck’s report indicates that all firmware versions on Zbtlink’s website contain this backdoor, with the process initiated at boot by an init.d script named “skworker.” Affected models include CPE2801, WE1026-5G-WD, and WG3526, among others, all dialing the same primary and secondary endpoints.

Response and Recommendations

In response to these vulnerabilities, Zbtlink has temporarily removed the affected firmware from their download page, indicating that their engineering team is working on secure updates. Meanwhile, users are advised to inspect their device processes and filesystem for suspicious files related to “kworker” and block the listed egress points.

The Hacker News has reached out to Zbtlink for a statement, and further updates will be provided when available. Users should remain vigilant and take recommended precautions to safeguard their devices against potential exploitation.

This situation underscores the importance of maintaining updated firmware and being aware of possible security risks associated with IoT devices.

The Hacker News Tags:backdoor vulnerability, cyber threat, Cybersecurity, ENDLESSDOORS, Firmware, Hacking, IoT security, Malware, network security, remote control, root shell, router security, VulnCheck, Zbtlink

Post navigation

Previous Post: Keyv Library Breach Sparks Major npm Supply Chain Threat
Next Post: Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses

Related Posts

New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper The Hacker News
Critical SGLang Vulnerability Allows Remote Code Execution Critical SGLang Vulnerability Allows Remote Code Execution The Hacker News
North Korean Hackers Combine BeaverTail and OtterCookie into Advanced JS Malware North Korean Hackers Combine BeaverTail and OtterCookie into Advanced JS Malware The Hacker News
Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime The Hacker News
New macOS Malware Forces Password Handover New macOS Malware Forces Password Handover The Hacker News
Active Exploitation of PAN-OS VPN Vulnerability Alert Active Exploitation of PAN-OS VPN Vulnerability Alert The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Security Flaws in AWS, Google, and Vercel Exposed
  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years
  • SQL Injection Exploits Oracle Database for SYSTEM Access
  • Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Security Flaws in AWS, Google, and Vercel Exposed
  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years
  • SQL Injection Exploits Oracle Database for SYSTEM Access
  • Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark