Researchers at VulnCheck have identified a persistent, previously undisclosed backdoor embedded in the firmware of a wide range of Chinese-manufactured routers. The vulnerability, named EndlessDoors by the research team, affects more than 20 specific models of networking hardware sold globally under both the Zbtlink and Wiflyer brand names.

Jacob Baines, CTO at VulnCheck, discovered the flaw while analyzing the device firmware. The backdoor functions as a persistent communication mechanism, where the compromised router automatically beacons to a specific IP address and a Chinese-registered domain every 35 seconds. This automated outbound communication suggests a structured infrastructure designed for command-and-control capabilities rather than legitimate network management or diagnostics.

“ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux). Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server. The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell,” Baines wrote in a post on the discovery.

The security implications of EndlessDoors are substantial. By exploiting this persistent connection, an attacker could potentially take control of the router, bypassing standard authentication measures. Once inside the gateway, the adversary would be positioned to conduct lateral movement, gaining access to other devices connected to the local network. This type of unrestricted access is not what you want. If these routers are deployed in sensitive environments such as research labs or small business networks, the backdoor provides an open portal for external entities to roam the network at will.

“Because the device dials out, none of this requires the router to be reachable from the internet. There's no listening port to find and no inbound rule to punch through. The connection originates inside the network and traverses NAT and typical egress filtering the way any outbound TCP session does. A unit sitting behind three layers of firewall in a hotel back office is exactly as reachable as one with a public IP, provided it can get to the C2,” Baines said. 

“That isn’t theoretical either. We translated the rctl server protocol into a go-exploit and hijacked the outbound rctl communications from our AX3000 client. After the AX3000 announced itself, we told it to give us an interactive shell. And it did.”

VulnCheck estimates that at least 100,000 of these routers are currently active in the wild, though the exact geographic distribution and specific number of units currently operational in the United States is tough to pin down. The discovery adds a new layer of concern to the broader issue of the supply chain security risks inherent in some networking equipment.

Baines found that every firmware image on the Zbtlink download page contains the implant. VulnCheck did not tell Zbtlink what it had found, reasoning that the implant is an intended feature and not a bug. 

“Coordinated disclosure exists to give a vendor time to fix a defect. It assumes the vendor did not intend the behavior. That assumption doesn't hold here. This isn't a memory corruption bug in a parser. It's a component in the vendor’s product, started at boot by the vendor's own init script, shipped across twenty models and years of images,” Baines said.  

“There is no patch to coordinate. Telling the shipper that they shipped it buys the owners of these devices nothing, and buys whoever operates that infrastructure a warning.”