Backdoor in Chinese‑Made Routers Exposes Homes and Small Offices to Remote Takeover
Security researchers have uncovered a root‑level backdoor, dubbed ENDLESSDOORS, in at least 20 models of Chinese‑made Zbtlink routers that can grant attackers a live shell without a password. The flaw puts home users, small businesses, and remote workers at risk of silent compromise that many traditional security tools will struggle to see.
A family of low‑cost routers used in homes and small offices around the world may be quietly surrendering full control to whoever knows the right way in. Security researchers have disclosed that at least 20 models of Chinese‑made Zbtlink routers ship with a built‑in backdoor, code‑named ENDLESSDOORS, that can open a live root shell without any authentication—even when the device is not directly exposed to the internet.
According to the technical analysis, the backdoor component is designed to start at boot and sit waiting in the background, effectively giving anyone with the requisite knowledge the ability to execute commands as the most powerful user on the device. Because it does not require a traditional login and can operate over non‑standard channels, many endpoint protection tools and basic firewalls are unlikely to detect its use.
For ordinary users, the risk is both simple and far‑reaching: a router compromised through ENDLESSDOORS becomes a foothold into everything connected behind it. That can mean access to laptops and phones on a home network, remote‑work endpoints tying into corporate systems, or the internal tools of a small business. Attackers who gain root access to the router can reroute traffic, inject malicious content, steal credentials, or quietly watch for sensitive data traversing the network.
The discovery touches a sensitive nerve in global cyber policy debates: the security of network hardware sourced from manufacturers operating under foreign jurisdictions. While the existence of a backdoor does not, in itself, prove that any state actor ordered it or has used it, it forces governments, enterprises, and consumers to confront the fact that critical infrastructure in homes and offices can harbor opaque code with extraordinary privileges.
Operationally, the ENDLESSDOORS case echoes a broader evolution in attacker tradecraft. At the same time as researchers are warning about backdoored routers, separate investigations have documented adversaries turning obscure features in enterprise systems into entry points—such as compiling tools like the “khunt” toolkit inside an Oracle database itself to gain Windows SYSTEM access without dropping conventional malware on disk. Both techniques aim at the same goal: living in parts of the stack that traditional security tools barely see.
For small businesses and remote workers, the appeal of cheaper, feature‑rich routers is obvious. But the downside is now harder to ignore. Devices that are not routinely patched, that lack transparent security documentation, or that include undocumented services can effectively put every invoice, design file, and customer record within reach of a patient attacker. Once a router is compromised, even careful endpoint hygiene may not be enough, because the network path itself has been subverted.
Governments and large enterprises have already begun tightening procurement rules for critical network equipment, often requiring security audits and source‑code reviews. The presence of a root‑level backdoor in widely sold consumer and SOHO gear will add fuel to arguments for extending similar scrutiny down‑market, or at least issuing clearer guidance to citizens about which devices are considered trustworthy.
The shareable insight is blunt: when the gateway to your network is compromised, every secure password and encrypted app behind it becomes a lot less meaningful. Trust cannot be retrofitted onto hardware that was not designed with transparency and verifiable controls in mind.
The next things to watch are whether Zbtlink issues firmware updates or recalls, whether other vendors are found to have similar hidden access mechanisms, and how regulators in key markets respond—through advisories, import restrictions, or new cybersecurity labeling schemes. Security teams will also be tracking exploitation attempts in the wild, looking for attackers who move quickly to weaponize ENDLESSDOORS before the vulnerable routers are patched or replaced.
Sources
- OSINT