Zbtlink routers, manufactured by Shenzhen Zhibotong Electronics and sold globally under multiple brand names including Wiflyer, contain a pre-installed backdoor implant named ENDLESSDOORS. This implant, based on the open-source rctl tool, runs as disguised userland processes named 'kworker' and continuously attempts to contact command and control servers. The backdoor provides unauthenticated remote root access through plaintext communication on ports 7000 and 7001, allowing attackers to execute arbitrary commands or spawn interactive shells without any verification. Twenty different router models are confirmed affected, all phoning home to four primary endpoints including zbtctl.epplink.net and hardcoded IP addresses hosted on Alibaba Cloud. The vulnerability is assigned CVE-2026-66747. No fixed firmware exists as the backdoor appears intentionally embedded by the manufacturer across multiple firmware versions spanning several years.
Created: 2026-08-06
Indicatorsは見つかっていない。
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。