HeadlinesBriefing favicon HeadlinesBriefing.com

Chinese Router Backdoor: ENDLESSDOORS Found

9to5Mac •
×

The most blatant security backdoor, dubbed ENDLESSDOORS, has been discovered in routers manufactured by Shenzhen Zhibotong Electronics and sold under various brand names like Zbtlink and Wiflyer. This firmware implant phones home to cloud servers in China for instructions, enabling remote control without requiring inbound access from the internet. This feature makes it particularly dangerous, as it can bypass firewalls and NAT.

This discovery follows previous concerns over Chinese routers, with the US government banning new imports due to national security risks. Thousands of Asus routers were previously compromised, and devices from Cisco, D-Link, and Linksys have also been targeted. A significant challenge is that these compromised routers are often rebadged and supplied by ISPs, leaving consumers unaware of their true origin.

Vuln Check, the cybersecurity company that identified ENDLESSDOORS, highlights its risk as the device initiates contact with its command and control servers. The backdoor uses a tool called `rctl` (remote control linux). Users can check if their router is affected by looking for specific model numbers, including WE1326 and WG3526. If a router matches one of the affected models, it should be immediately disconnected and replaced.