VMTech
Discuss a project

VulnCheck identifies root-shell backdoor in 21 Zbtlink router models

VulnCheck identifies root-shell backdoor in 21 Zbtlink router models

Security researchers at VulnCheck have identified a factory-shipped backdoor in 21 Zbtlink router models. The implant, dubbed ENDLESSDOORS, was present in all 21 firmware images available from Zbtlink that VulnCheck examined, covering more than two years of releases.

The researchers analysed a Zbtlink AX3000 device and found a process named kworker that masquerades as a Linux kernel thread. It is instead a userland process running with root privileges. The implant is started at boot by an init.d script named skworker and attempts to contact Chinese command-and-control infrastructure as often as every 35 seconds.

An unauthenticated command channel

VulnCheck said ENDLESSDOORS is built around a small remote-control tool called rctl. Its server listens on port 7000 and can issue individual shell commands to a connected client or instruct it to create a reverse Bash shell.

On the affected routers, the customised rctl client sends a hello message containing the device LAN MAC address. There is no handshake, negotiation or authentication before it executes a response from the server. The reserved command rctlbash opens a second connection to port 7001, allocates a pseudo-terminal, launches /bin/sh and bridges the session, creating an interactive root shell.

That design means an actor able to intercept the outbound client-server traffic, control the resolution of the configured domain, or control the resolved address could take control of an implant. The router does not need to be reachable directly from the internet for that takeover path to work. The finding adds a supply-chain dimension to Linux rootkits and router zero-day risks, where router security risks can create privileged access inside a local network.

Firmware removed while remediation is prepared

VulnCheck said every firmware image listed on Zbtlink's download page embedded rctl and used the same four primary and secondary endpoints: zbtctl.epplink[.]net, 47.107.224[.]89, online-string[.]com and rbdg4nzqadui.wikaba[.]com. The affected products include CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526 and Z8102AX-2DSIM.

Zbtlink's download page states that selected vulnerable firmware releases have been temporarily removed and that its engineering team is developing and validating secured patched firmware. Until validated releases are available, customers can check process lists and scan for /usr/sbin/kworker, /usr/lib/librctl.so, /etc/kworker.cfg and /etc/init.d/skworker, while blocking the identified egress destinations.

Business implication

Organisations operating these routers should treat the devices as potentially compromised infrastructure: identify affected models, restrict their outbound communications and plan isolation or replacement decisions alongside deployment of security-validated firmware.

#cybersecurity#routersecurity#firmwaresecurity#iotsecurity
Open analytics
On the site 1 views
min read 3 06.08.2026
Instagram

VulnCheck identifies root-shell backdoor in 21 Zbtlink router models

Open the post on Instagram ↗