DistantNews
Support us
๐Ÿ‡น๐Ÿ‡ผ Taiwan /Technology

Chinese-Made Routers Contain Hidden Backdoor, Affecting 100,000 Devices Globally

From Liberty Times · () Chinese

Translated from Chinese, summarized and contextualized by DistantNews.

At a glance

News Sources not specified Context piece
  • A cybersecurity firm, VulnCheck, has discovered a previously undisclosed "hidden backdoor" in over 20 models of routers manufactured by Chinese company Zbtlink.
  • These routers, sold under the Zbtlink and Wiflyer brands, automatically connect to a specific IP address and a Chinese domain every 35 seconds, potentially allowing remote control.
  • An estimated 100,000 units are in use globally, posing a significant security risk, particularly for businesses and home offices, though there is no current evidence of the backdoor being exploited.

Cybersecurity firm VulnCheck has revealed a significant security vulnerability, dubbed "Endlessdoors," affecting over 20 router models produced by the Chinese manufacturer Zbtlink. These routers, marketed under both the Zbtlink and Wiflyer brands, contain a hidden backdoor that allows for potential remote control and subsequent intrusion into networks.

According to VulnCheck's research, led by CTO Jacob Baines, the affected routers establish an automatic connection to a specific IP address and a registered domain in China every 35 seconds. This constant communication channel could be exploited by malicious actors who control the server to gain command over the routers. From there, attackers could access other devices within the same local network, such as computers, network-attached storage (NAS) devices, and surveillance cameras.

VulnCheck estimates that at least 100,000 of these routers are currently in use worldwide, although the exact distribution and operational status remain unclear. The firm notes that these devices are commonly found in small businesses and home office environments, where users are unlikely to suspect any underlying security risks.

These routers connect to a specific IP address and a Chinese registered domain every 35 seconds. If the person controlling that server issues a command, they could gain control of the router and access other devices on the local network.

โ€” Jacob BainesVulnCheck's CTO explained the mechanism of the 'Endlessdoors' vulnerability.

Baines emphasized the severity of the vulnerability, stating that deploying these devices in corporate settings, laboratories, or research institutions is akin to opening a direct entry point for external threats. He described the potential for attackers to move freely within an internal network after gaining control as "highly destructive."

While there is currently no evidence that this backdoor has been actively exploited by hackers, nor is its original purpose confirmed, Zbtlink has yet to respond to VulnCheck's findings. This discovery comes amid ongoing security concerns raised by the United States and other Western nations regarding Chinese-made network equipment, which they fear could be used for espionage or cyberattacks. In March, the U.S. Federal Communications Commission (FCC) restricted the import of certain foreign-made consumer routers on national security grounds.

If such devices are deployed in enterprises, laboratories, or research institutions, it is equivalent to actively opening an entrance for outsiders.

โ€” Jacob BainesJacob Baines described the high security risks associated with the backdoor in professional environments.
DistantNews Editorial

Originally published by Liberty Times in Chinese. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.