Multiple cybersecurity sources report that Chinese-made Zbtlink routers include a “factory-shipped” backdoor. Researchers say the implant enables remote access that can provide root-level control without authentication, including an “unauthenticated root shell.” The issue is described as present across a broad range of Zbtlink firmware versions available over an extended period. One report, attributed to VulnCheck, states the backdoor appears in all Zbtlink firmware images currently available, totaling 21 images, and spanning more than two years. The accounts also describe the backdoor as starting automatically when the device runs and then attempting to contact an external endpoint, described as beaconing to China. The reports indicate the affected scope includes at least 20 router models, based on the set of products and firmware variants reviewed by researchers. The disclosures focus on the backdoor’s behavior and technical characteristics rather than confirmed real-world exploitation. The information is presented as a vulnerability disclosure intended to inform users, network administrators, and manufacturers about potential unauthorized control risks.
Researchers find factory backdoor in Zbtlink routers shipped with unauthenticated root access
Multiple cybersecurity sources report that Chinese-made Zbtlink routers include a “factory-shipped” backdoor. Researchers say the implant enables remote access that can provide root-level control with...
- Researchers report a factory-shipped backdoor in Zbtlink routers.
- The backdoor is described as enabling unauthenticated root-level access (root shell).
- A VulnCheck report says the implant appears in all 21 Zbtlink firmware images currently available.
- The affected firmware/product scope is described as spanning more than two years and at least 20 router models.
- Sources say the backdoor starts automatically and attempts to beacon/contact an external endpoint described as in China.
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese
3 hours agoResearchers found a backdoor implant that gives servers in China full control over the routers.
12 hours ago
London councils threaten to defy EHRC guidance on single-sex spaces
Several left-leaning London councils say they may not follow new guidance on single-sex spaces prepared by the Equality...
Corruption barrister calls for removal of union boss Peter Marshall
Top anti-corruption barrister Geoffrey Watson says union leader Peter Marshall should be removed from his position, argu...
Scientists warn illegal trawling may cause collapse of Britain’s haddock stocks
Scientists warn that Britain’s haddock stocks face serious decline, linking the risk to illegal fishing practices by tra...