"Zbtlink routers phone home, waiting for orders. Not because they were hacked. Because they were shipped that way." That is how Jacob Baines, chief technology officer at threat-intelligence firm VulnCheck, characterized software he says is present on Zbtlink-made routers.
VulnCheck's allegation and the decision to publish
VulnCheck published a technical post accusing Chinese router vendor Zbtlink of shipping a built-in command-and-control client it calls "ENDLESSDOORS." Jacob Baines wrote that he observed the implant running on a device in his possession and concluded the component was started at boot by the vendor's init script and present across "twenty models and years of images." He decided not to follow coordinated disclosure procedures, arguing the behavior appeared intentional: "Coordinated disclosure exists to give a vendor time to fix a defect. It assumes the vendor did not intend the behavior."
Technical claims about ENDLESSDOORS and rctl
Baines linked the implant to a small tool called rctl, which he says was uploaded to GitHub on January 14, 2015 and "never touched again." According to VulnCheck's description, the server side listens on port 7000 and can deliver individual shell commands or instruct the client to spawn a reverse bash shell. Baines wrote the implant registers by sending a fixed 39-byte "hello": a 33-byte class label padded with nulls followed by the device's LAN MAC address, and he emphasized there is "no handshake, no key exchange, no negotiation." The CTO warned that “anyone along the network path can hijack the client/server communication,” and noted that devices VulnCheck tested contacted four endpoints, only one of which used a domain name linked to Zbtlink; VulnCheck identified one endpoint as rbdg4nzqadui[.]wikaba[.]com, a connection Baines labeled "damning."

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageZbtlink's public denials and the paused firmware downloads
The Register sought comment from Zbtlink. A company spokesperson told The Register that VulnCheck had "mischaracterized the code it found" and said the feature was "solely intended for after-sales maintenance" and "generally retained only on sample units to assist customers with software debugging and will not be included in mass‑production shipments." Despite that denial, The Register observed that Zbtlink's public download page carries a notice titled "Update on Router Firmware Security Remediation" stating: "We have detected firmware security vulnerabilities affecting selected router firmware releases. As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. Our engineering team is working intensively to develop and validate secured patched firmware." The Wayback Machine snapshot from July 31 contained no such admission and showed a long list of firmware downloads.
Sales channels, OpenWrt support, and customization risk
VulnCheck reported Zbtlink-branded kit is sold under names including ZBT, ZBTWiFi and Wiflyer and found devices listed on Amazon, Alibaba and Shopify. Zbtlink told The Register it "specializes in OEM and ODM customization services" and that customers often install their own software rather than Zbtlink's default firmware. The Register noted the OpenWrt open‑source router firmware project supports at least one Zbtlink product, and that Zbtlink has previously promoted options enabling clients to rapidly create custom firmware packages. Taken together, VulnCheck and The Register highlighted how OEM/ODM practices and documented OpenWrt support could expand where custom code appears on deployed devices.
What this means for technologists, procurement leaders, and home users
- Technologists and security teams: VulnCheck published detection guidance and provided Suricata, Snort, and YARA rules that it says will block access to the endpoints the routers contact. Baines also advised defenders to treat affected devices behind "strict egress control" and to detect the implant's userland processes running as root.
- Procurement leaders and OEM/ODM customers: Zbtlink's statement that customers often install bespoke firmware, combined with the company's prior promotion of OpenWrt support, underscores the need for buyers to verify the software image present on devices and to demand transparency about any vendor debug or maintenance features retained on samples versus production units.
- Home users and small enterprises: VulnCheck recommended replacing impacted devices or, at minimum, putting them behind strict outbound filtering and treating the local network as untrusted until firmware is patched or devices are replaced.
The factual record in public statements is sharply divided: VulnCheck says a boot-started implant based on an old rctl repository phones home without verification and appears across many images; Zbtlink says the behavior is a maintenance feature kept on sample units and claims it will not be in mass‑production shipments while simultaneously removing selected firmware from download channels to patch "security vulnerabilities." The Register also noted router firmware is a plausible target for supply‑chain attack. For now, the immediate steps are concrete: Zbtlink has paused affected firmware downloads while it develops patched images, and VulnCheck has published detection and egress‑blocking rules for defenders to use.
Original reporting: The Register — Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway




