VulnCheck finds three hidden backdoors in ZBT-made routers sold under many brand names
Security firm VulnCheck discovered three separate backdoor-like implants embedded in firmware made by Shenzhen Zhibotong Electronics (ZBT), whose hardware is resold globally under numerous brand names. The most severe, dubbed ENDLESSDOORS, disguises itself as a Linux kernel process, phones home to a hard-coded command server without authentication or encryption, and grants attackers root-level control over the router. VulnCheck confirmed the flaw is real by hijacking a test router's command channel themselves, and identified it across 20 ZBT-based router models.