Zbtlink Halts Router Sales After Researchers Find Remote-Control Backdoor
Zbtlink suspended sales of affected routers and removed firmware downloads after VulnCheck researchers reported a remote-access component that could potentially give attackers root-level control.
Why it matters: Router firmware and remote-support tools can become supply-chain attack paths when authentication and control fail.
Router manufacturer Zbtlink has suspended sales of affected devices after cybersecurity researchers discovered a remote-management mechanism that could potentially give attackers root-level control of deployed routers.
VulnCheck researchers found the component across roughly two dozen firmware images and named the issue ENDLESSDOORS. Their analysis showed affected routers making outbound connections to command-and-control infrastructure and accepting commands without strong authentication.
Because the connection originates from inside the network, an affected router could remain exposed even when protected behind common firewalls or network-address translation.
Zbtlink says the component was designed solely as an after-sales technical-support tool and was intended to be used only when customers explicitly authorized remote assistance. The company says it has never been used for unauthorized access.
The incident highlights an enduring enterprise-security problem: remote-management functions embedded in networking hardware can become high-value attack paths if authentication, ownership or update controls fail.