Security researchers at VulnCheck disclosed on Aug. 5 that at least 20 consumer and small-business router models made by Chinese manufacturer Zbtlink ship with a factory-installed remote-access backdoor. Unlike malware installed after purchase, the software researchers discovered is already present when the router leaves the factory. Why researchers call it a backdoorAccording to VulnCheck, the software establishes a persistent outbound connection without authentication or cryptographic verification. VulnCheck says the confirmed list currently includes 20 models, but because Zbtlink also produces hardware for third-party brands, additional rebranded devices could be affected. "This is an after-sales technical support component rather than a malicious backdoor, and updated firmware is being prepared," Zbtlink said in its response after VulnCheck published its findings.