None
EN
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
['The Hacker News', 'Ravie Lakshmanan', 'Aug']
The Hacker News
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.
According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years.
"ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux)," Jacob Baines, VulnCheck Chief Technology Officer, said.
"The vocabulary of this protocol is two phrases: run this as root, and give me a root shell.
]125)As of writing, users visiting the firmware downloads page on Zbtlink's website are displayed the below message -We have detected firmware security vulnerabilities affecting selected router firmware releases.