
Researchers at cybersecurity firm VulnCheck reported that more than 20 models of a Chinese-made router sold worldwide contain a previously unreported backdoor the researchers called “Endlessdoors”. Jacob Baines, VulnCheck’s chief technology officer, said the backdoor appears in multiple models manufactured and sold by Zbtlink under the Zbtlink and Wiflyer brand names. The backdoor automatically communicates to a specific IP address and a Chinese-registered domain every 35 seconds. Whoever controls those domains could take control of the router and potentially access other devices on the same network. Zbtlink did not respond to a request for comment.
Baines estimated at least 100,000 such routers are deployed globally but said it is not possible to say exactly where they are or how many are active in the United States. Western governments have for years warned that small office and home office routers can be abused for intrusions and cyberespionage. Reuters said it could not determine why the backdoor exists or whether it has ever been abused, and Beijing denies condoning cyberattacks.
Some reporting and official responses treat Chinese-made networking equipment as a broad national-security risk; that framing can feel alarming and may imply state intent even where evidence is thin. The technical finding here is serious – an automatic connection to external domains that could allow remote control – and regulators have already restricted or scrutinised imports on security grounds. At the same time, researchers and Reuters say they could not determine the backdoor’s purpose or any instances of abuse, and deployment estimates are uncertain. A balanced approach for readers is to take the technical risk seriously while recognising the limits of current evidence about intent and impact.
Original article: Why experts are flagging Chinese company Zbtlink’s routers as a potential cybersecurity risk (www.hindustantimes.com)
This story was summarised and commented on by AI from the source linked above.