Recently, American researchers have revealed that more than 20 models of routers produced by the Chinese company Zbtlink based in Shenzhen are found to have pre-installed backdoors. This backdoor program automatically communicates with a specific IP address and a domain name registered in China every 35 seconds.
The discovery of this backdoor was made by the cybersecurity company VulnCheck based in Massachusetts. Jacob Baines, the Chief Technology Officer, disclosed in a blog post on Wednesday that the backdoor, dubbed “Endlessdoors,” was identified for the first time.
The backdoor is present in various models of routers produced and sold by Zbtlink, mainly under the Zbtlink and Wiflyer brands. Reports indicate that routers manufactured by Zbtlink are sold worldwide.
Zbtlink has not responded to the issue.
Baines estimated that there are at least 100,000 of these problematic routers operating globally, but it is unclear where they are deployed or how many are active in the United States.
The backdoor program discovered by researchers automatically communicates with a specific IP address and a domain name registered in China every 35 seconds. Baines pointed out that those controlling these domains could manipulate the routers and potentially exploit them to access other devices on the same network.
Most users who purchase these routers are for small businesses or home offices, and they may not be aware that the router automatically allows such backdoor access.
“If I were to put it in my lab, put it in my university lab, you’re essentially inviting them directly into your lab, and they can roam around the network at will,” Baines said. “This capability is devastating.”
In addition, Zbtlink also provides OEM services. If routers from other brands use the same set of hardware and firmware from Zbtlink, they may also contain the same implants.
The reasons for the existence of this backdoor program, its purpose, and whether it has been abused are uncertain.
Baines stated that they believe the vulnerabilities of these routers are unpatchable because it involves a component in the supplier’s product that was designed from the beginning.
He explained that according to industry norms, vendors should be notified of vulnerabilities and given time to fix the flaws, but this was not feasible in this case.
“The purpose of coordinated disclosure is to give vendors time to fix flaws. It assumes that the vendors did not intentionally create this behavior. However, this assumption does not hold in this case,” the article stated.
“This is not a memory corruption vulnerability in the resolver, it’s a component in the supplier’s product, started by the supplier’s own init script at boot and has appeared in over twenty models, mirror versions for years. So, there’s no patch available,” Baines said.
Baines mentioned that they chose to directly disclose this incident to avoid alerting the wrongdoers. “Notifying the vendors of their discovered vulnerabilities does no good to the owners of the devices, it only serves as a warning to the personnel operating the infrastructure,” he wrote.
Researchers recommend purchasing reliable router devices and not relying solely on patching to mitigate network attack risks.
The discovery of this backdoor exacerbates concerns in Western countries about the network security risks associated with Chinese-manufactured networking equipment. Over the years, various Western governments have warned that hackers could exploit such devices, and this year the U.S. regulatory agency took action to restrict the import of foreign-manufactured routers.
In March, the Federal Communications Commission (FCC) announced that for national security reasons, it would ban the import of new consumer-grade routers manufactured abroad, but later the organization exempted many products from non-Chinese companies.
In February, Texas sued the California-based router manufacturer TP-Link (the company was spun off from a Chinese company), accusing the company of allowing Beijing access to devices used by American consumers. TP-Link denied the allegations.
