Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Zbtlink Routers Found with Hidden Remote-Access Feature Affecting More than 20 Models

Zbtlink Routers Found with Hidden Remote-Access Feature Affecting More than 20 Models

By:
Last updated:August 10, 2026
Human Written
  • More than 20 Zbtlink router models contain a hidden remote-access feature that can give an outside party powerful control of the device.

  • The routers contact a Chinese-registered domain every 35 seconds, creating a path for remote control without direct access to the router.

  • Zbtlink says the feature was made for customer support, but security researchers question why it was hidden and built without stronger safeguards.

Zbtlink Routers Found With Hidden Remote-Access Feature Affecting More than 20 Models

A security finding involving more than 20 routers made by Chinese company Zbtlink is raising new questions about the safety of network equipment sold around the world.

Researchers at cybersecurity firm VulnCheck found a hidden remote-control feature in several Zbtlink router models. The devices are also sold under the Wiflyer name.

VulnCheck CTO Jacob Baines discovered the issue while examining a Zbtlink router in his lab. He found that the device repeatedly tried to contact a specific internet address. The connection happened about every 35 seconds.

The researchers called the hidden feature “Endlessdoors.” This particular vulnerability can give an outsider high privilege access. They could send high-privilege commands to the router directly without authorization.

This is a big deal because a router is often at the center of a network. It can connect your computers, phones, cameras, servers, and a lot of other devices. If an attacker takes control of the router, the risks won’t stop at just the router. Everything connected could be in trouble.

The Outbound Connection Poses the Biggest Concern

The problem is not simply that the router contains remote-management code. Many modern network devices have remote support and management tools. Vendors use them to troubleshoot problems, update software and help customers.

The concern here is how the Zbtlink feature works. According to VulnCheck, the router itself starts the connection to a specific IP address and a domain registered in China. It does this automatically.

An attacker would therefore not necessarily need to find an open management port on the router. Instead, the router reaches out first.

According to Baines, whoever has control of the destination can gain control over the router and use it to communicate with other devices in the network.

Based on VulnCheck’s report, this may have affected at least 100,000 routers already in use around the world. However, there’s no way to know exactly where they are and how many of them are still active.

Zbtlink has released a statement rejecting the suggestion that they designed the feature as a spying tool.

After the research became public, the company said that they designed the feature for after-sales technical support. They intended for it to help customers troubleshoot and set up devices after receiving their explicit permission.

The company also said the feature had never been exploited for unauthorized access. Zbtlink then suspended sales of affected routers and removed vulnerable firmware from its website while it worked on updates.

That response does not settle the main question for security researchers. Baines has questioned why the feature was difficult to identify and why it used an insecure design that hackers could hijack.

The company’s explanation also conflicts with another detail raised by researchers. VulnCheck found the feature across multiple firmware versions and router models, rather than in one isolated test device.

No Evidence yet of Attacks Against Users

One important fact has received less attention. Currently, there’s no public evidence that attackers have targeted customers using the feature.

Reuters reported that they haven’t been able to determine why the backdoor existed. Also, they’ve not identified who may have controlled the related infrastructure or whether anyone had abused it.

That distinction is important. Finding a hidden access method does not prove that a company used it for spying. It also does not prove that the Chinese government was involved.

The immediate security problem is the design itself. If a remote attacker can take over a router because the device automatically connects to infrastructure that can be hijacked, the weakness can create a serious risk even without malicious action by the manufacturer.

The Finding Adds to Wider Router Security Concerns

This finding comes at a time when there is heightened interest in the security of internet routers by governments.

Routers have become easy prey because they form the connecting link between the user and the internet. A weakness in a router device can give attackers the opening they need to carry out further attacks.

U.S. authorities have also warned about China-linked hacking groups targeting small-office and home-office routers.

In March, the FCC announced restrictions on new foreign-made consumer routers citing national security concerns. The agency later exempted many non-Chinese manufacturers. Zbtlink is not the first router maker to face security problems.

The targeting of routers and network infrastructure is not limited to hardware backdoors; Iranian state-backed hackers have recently launched a campaign called Operation Olalampo targeting routers, VPNs, and network gateways across the Middle East and North Africa to gain persistent access to corporate and government networks.

The company itself lists several earlier vulnerabilities affecting its firmware and cloud services. Those flaws included command injection and weaknesses that could allow attackers to gain control of routers.

The latest discovery is different because researchers describe the feature as a built-in remote-control mechanism rather than a normal software bug.

What Users Should Do Now

Users of Zbtlink or Wiflyer routers need to determine their specific models and firmware versions.

For routers with the vulnerability, experts suggest disconnecting them from critical networks until a proven solution is available.

Zbtlink says it is developing patched firmware and has already removed affected software from its download channels.

For businesses, schools and other organizations, the stakes are higher. It’s wrong to treat a router as an isolated device because it can provide a path into the wider network.

The discovery does not prove a Chinese espionage campaign. It does, however, show why hidden remote-access features in network equipment deserve close scrutiny, regardless of who makes the device.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.