LIVE · cybersecurity feed
Live wire
CISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksCritical Avada WordPress theme flaw enables zero-click RCECVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
security

Chinese Routers Sold Worldwide Contain Backdoors

An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.

zeroday.news ·

Reports indicate that an unspecified number of ZBT-manufactured routers, distributed globally as white-label products, have been found to contain multiple pre-installed implants. These implants are reportedly integrated into the devices by the manufacturer.

The nature of these implants suggests they could facilitate unauthorized access or control over the affected routers. Such backdoors typically involve hidden functionalities or credentials that bypass standard security mechanisms, potentially allowing remote access to the device's configuration, network traffic, or even the ability to push further malicious updates. This class of vulnerability often exploits weaknesses in firmware design or manufacturing processes, where non-standard access points are intentionally or unintentionally left active.

ZBT, a manufacturer of networking equipment, appears to be the source of these devices. The "white-label" distribution model means these routers are sold under various brand names by different vendors, making it challenging for end-users to identify the original manufacturer and, consequently, the potential vulnerability. Products in this category commonly serve small businesses, home offices, and general consumer markets, where the expectation of robust security vetting by the reseller may vary.

The scope of this issue is currently unknown, as the reports do not specify the number of affected units or the extent of their global distribution. Given the white-label nature, the devices could be present in a wide array of environments, from individual homes to enterprise networks that have integrated these lower-cost networking solutions. The lack of specific model numbers or firmware versions also complicates the identification and remediation process for users.

Mitigation for this class of issue typically involves isolating the affected devices, if they can be identified, and replacing them with trusted hardware. For devices that cannot be immediately replaced, users are generally advised to ensure they are running the latest available firmware from their specific reseller, though in cases of manufacturer-embedded backdoors, firmware updates may not fully resolve the issue. Network segmentation and strict firewall rules can help limit the potential impact of a compromised router on the broader network.

This incident underscores the growing concerns about supply chain security in hardware manufacturing, particularly for devices originating from regions with complex geopolitical landscapes. The presence of manufacturer-installed backdoors highlights the inherent trust placed in hardware vendors and the potential for that trust to be exploited, raising questions about the due diligence performed by resellers and the broader implications for national and enterprise cybersecurity.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

White House bans foreign-made equipment for power generation over cyber backdoor concerns

The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.

breach

AI girlfriend review site's secrets were exposed to the world for three weeks

Even testing and staging sites need protection from prying eyes

vulnerabilityhigh

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]

breach

OpenAI: Hugging Face Incident a “Warning Shot” to the World

OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach

securitycritical

US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWeek.

nation-state

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.