A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a router on his desk that kept trying to call home, and it wasn’t supposed to. VulnCheck researchers found a backdoor baked into Zbtlink routers, and it’s not the kind of […]

Security researchers have uncovered a hidden backdoor present in 20 models of Zbtlink routers, a Chinese manufacturer also known as Shenzhen Zhibotong Electronics. This backdoor, which the researchers have named ENDLESSDOORS, allows remote servers to execute commands with root privileges, potentially leading to full device compromise. Zbtlink routers are sold under various brand names, including Wiflyer, ZBT, and ZBTWiFi, through platforms like Amazon, Alibaba, and Shopify.
The discovery originated when a researcher observed an unexpected outbound connection attempt from a Zbtlink AX3000 router. Further investigation revealed two processes named `kworker` running as root, with active memory footprints, alongside legitimate Linux kernel threads of the same name. These unbracketed `kworker` processes are not genuine kernel threads but rather userland processes designed to blend in with legitimate system activity.
The ENDLESSDOORS implant functions as a phone-home trojan. It connects to a hardcoded server and, once a connection is established, transmits a fixed 39-byte "hello" message consisting of a 33-byte class label padded with nulls, followed by the router's LAN MAC address. Crucially, the researchers found no client or server verification mechanisms in place. After this initial registration, any data sent by the command server is passed to the `popen()` function and executed as `uid 0`, granting root access without any allow-listing or sandboxing.
A specific string, "rctlbash," instructs the implant to open a second connection to port 7001, allocate a pseudo-terminal, spawn `/bin/sh`, and bridge it, effectively providing a live, interactive root shell. This means an attacker controlling the command server could obtain a remote login to the router without requiring a password. Because the router initiates the connection, standard firewall rules designed to block incoming connections are ineffective, leaving devices behind multiple layers of corporate firewalls just as vulnerable as those directly exposed to the internet, provided they can reach the command server.
To demonstrate the exploit, the researchers developed a tool that impersonated the command server. They successfully intercepted the router's outbound connection and obtained a root shell within seconds. The backdoor is automatically launched at boot through an `init` script named `skworker` across all affected models.
The researchers identified that the entire fleet of compromised routers connects to a small set of four primary and secondary endpoints. These endpoints are hosted across Alibaba Cloud, Vultr, and a Chinese cloud provider. This centralized infrastructure implies that whoever controls these servers could simultaneously control all affected routers globally. The primary endpoints include `zbtctl.epplink[.]net` (resolving to 47.100.190[.]96 on Alibaba Cloud, Shanghai) and a hardcoded IP address (47.107.224[.]89 on Alibaba Cloud, Shenzhen). Secondary endpoints are `online-string.com` (resolving to 45.32.81[.]152 on Vultr) and `rbdg4nzqadui[.]wikaba[.]com` (resolving to 43.248.136[.]125 on Jiangsu Dongyun Cloud).
The researchers opted against a coordinated disclosure process with the vendor, citing that the backdoor appeared to be an intentionally built-in component, present across numerous models and firmware releases over several years. They believed that warning the vendor would only alert those operating the malicious infrastructure.
Zbtlink, in response to inquiries, claimed the backdoor was solely for "after-sales maintenance" and was not intended for mass-production shipments, stating it was only retained on sample units for software debugging. However, the company subsequently removed firmware downloads from its website and acknowledged unspecified "firmware security vulnerabilities," which has raised further questions regarding its explanation.
Given that this is a vendor-built "feature," no patch is expected. Users of affected Zbtlink router models are advised to consider their devices compromised by design. It is crucial to check the specific model number, as the same hardware can be rebranded under different names.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets