Researchers flag backdoor in Chinese-made Zbtlink routers

Why experts are flagging Chinese company Zbtlink’s routers as a potential cybersecurity risk

Cybersecurity firm VulnCheck says more than 20 router models sold worldwide under the Zbtlink and Wiflyer brand names contain a previously unreported backdoor its researchers have named Endlessdoors. VulnCheck's chief technology officer,…

Cybersecurity firm VulnCheck says more than 20 router models sold worldwide under the Zbtlink and Wiflyer brand names contain a previously unreported backdoor its researchers have named Endlessdoors. VulnCheck's chief technology officer, Jacob Baines, said the affected routers automatically contact a specific IP address and a China-registered domain every 35 seconds, and that whoever controls those domains could potentially take control of the router and reach other devices on the same network. Baines estimated at least 100,000 of the routers are deployed worldwide, though he said it is not possible to say exactly where or how many are currently active. Zbtlink did not respond to a request for comment. Reuters reported that it could not determine why the backdoor exists, what purpose it serves, or whether it has ever been exploited, and noted that Beijing routinely denies condoning cyberattacks.

Researchers Warn of Backdoor in Zbtlink and Wiflyer Routers

Indian Opinion Analysis

That a single compromised router can open a path to every other device sharing its network is what makes this worth taking seriously, and VulnCheck's tally of at least 100,000 units in the wild points to genuine reach. What nobody has pinned down is motive: not VulnCheck, not Reuters, can say who is behind Endlessdoors, what it was built to do, or whether anyone has actually used it to break into a network. The report sets the finding against years of Western government warnings about Chinese-made networking equipment and the Federal Communications Commission's March decision to ban imports of new foreign-made consumer routers, which later exempted many non-Chinese firms. What comes next is whether Zbtlink responds at all, and whether VulnCheck's researchers identify who controls the IP address and China-registered domain the routers contact every 35 seconds.


Source: www.hindustantimes.com

This brief was synthesised by AI from the source linked above.

Ask their opinion on this story
They have read this article, our coverage, and the web.
AI simulations of historical figures. Responses are generated from the historical record, not authentic statements.

0 Votes: 0 Upvotes, 0 Downvotes (0 Points)

Share your opinion

Loading Next Post...
Search Trending
Ask their opinion
Loading

Signing-in 3 seconds...

Signing-up 3 seconds...

All fields are required.