logo

Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access

ID: 412c6bfd-aec3-51c4-91a6-f1418647034f

STIX ID: report--412c6bfd-aec3-51c4-91a6-f1418647034f

Feed Name: Security Affairs

Threat Score
82/100

Date Published: 2026-08-07

Date Updated: 2026-08-07

Author: Pierluigi Paganini

...
...

VulnCheck researchers discovered a built‑in backdoor (named ENDLESSDOORS) in 20 Zbtlink-based router models that automatically phones home to hardcoded command servers and executes any received commands as root (including spawning an interactive root shell); the implant is vendor-supplied, present across multiple rebranded devices, connects to four known endpoints hosted on cloud providers, and there is no available patch—affected devices should be treated as compromised and replaced or isolated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.