China's Zbtlink Halts Sales of 20+ Routers Over Backdoor Fears; Canada Issues Alert
Translated from Chinese, summarized and contextualized by DistantNews.
At a glance
- Chinese network equipment maker Zbtlink Electronics announced it will halt sales of over 20 router models found to contain a backdoor vulnerability.
- The backdoor, dubbed 'Endlessdoors' by security researchers, could allow unauthorized access and control of devices, potentially affecting other network-connected equipment.
- Zbtlink claims the program was a "technical support tool" used only with explicit customer authorization, but security experts question its hidden nature and insecure implementation.
Chinese network equipment manufacturer Zbtlink Electronics has announced a halt in sales for more than 20 router models following the discovery of a significant backdoor vulnerability. The issue came to light when cybersecurity firm VulnCheck identified the backdoor in routers produced by the Shenzhen-based company.
The vulnerability, named 'Endlessdoors' by VulnCheck's CTO Jacob Baines, reportedly allows malicious actors to access and control affected devices. It could also potentially compromise other devices connected to the same network. Zbtlink stated it is developing a software update to address the problem and has removed the affected software from its official website.
The backdoor program was purely an after-sales technical support tool, used only to assist with device troubleshooting and configuration when customers explicitly requested and authorized it, and was never used for unauthorized access.
Zbtlink defended its position, asserting that the backdoor program was intended solely as an "after-sales technical support tool." The company claims it was only used to assist with device troubleshooting and configuration when explicitly requested and authorized by customers, and that it was "never used for unauthorized access."
However, security researchers remain skeptical. Baines noted that the backdoor automatically connects to a specific IP address and a domain registered in China every 35 seconds. He questioned why such a tool would use a deliberately obscure name and an insecure implementation method prone to hijacking. Canada has issued a security alert regarding the vulnerability, reflecting growing international concern over the security risks associated with Chinese networking equipment.
The routers deployed globally are still at risk of being maliciously taken over via this backdoor.
Originally published by Liberty Times in Chinese. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.