All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

China's Zbtlink suspends router sales over backdoor vulnerability

Created at 6 Aug · 6:23 PM1 source↑ Market-relevant
IN SHORT

Chinese router maker Zbtlink Electronics is suspending sales of affected models and removing software after a cybersecurity firm discovered a backdoor vulnerability. The flaw could allow unauthorized access and control of devices on a network.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

20router models found with backdoor

Who's Involved

Zbtlink Electronics
Chinese router maker suspending sales due to backdoor
VulnCheck
Cybersecurity firm that identified the backdoor
Jacob Baines
CTO of VulnCheck who discovered the backdoor
Canadian government
Issued security advisory on affected routers

↳ Why This Matters

The discovery of a backdoor in Zbtlink routers raises significant cybersecurity concerns, particularly given Western scrutiny of Chinese networking equipment. The vulnerability could expose sensitive data and compromise entire networks, impacting both consumers and businesses.

Key facts

  • Zbtlink Electronics is suspending sales of routers found to contain a backdoor.
  • The vulnerability, dubbed "Endlessdoors," was identified by cybersecurity firm VulnCheck.
  • The backdoor could allow unauthorized access and control of the router and other network devices.
  • Zbtlink stated the backdoor was intended solely for after-sales technical support.
  • The Canadian government issued a security advisory regarding the router vulnerability.

Chinese router manufacturer Zbtlink Electronics has announced a suspension of sales for routers found to contain a backdoor vulnerability, and is removing the affected software from its website while developing updates. The cybersecurity firm VulnCheck identified the flaw, dubbed "Endlessdoors," in at least 20 models of routers produced by the Shenzhen-based company.

According to VulnCheck CTO Jacob Baines, the backdoor could allow unauthorized access and control of the device, potentially extending to other devices on the same network. Zbtlink stated that the backdoor was intended solely as an after-sales technical support tool, designed to assist customers with troubleshooting and configuration only upon explicit request and authorization, and has never been used for unauthorized access.

Revelations of the backdoor come amid heightened Western concerns regarding cybersecurity and the risks associated with Chinese-made networking equipment. The Canadian government issued a security advisory on Wednesday concerning the vulnerability. Baines noted that the backdoor automatically connected to a specific IP address and a Chinese-registered domain every 35 seconds, and that routers globally remain vulnerable to hostile takeover. He advised users to remove affected routers from their networks and monitor for compromise.

Frequently asked questions

Endlessdoors is a backdoor vulnerability discovered in Zbtlink routers that could allow unauthorized access and control of the device and other network-connected devices.

Zbtlink claims the backdoor was intended solely as an after-sales technical support tool for customer-requested troubleshooting and configuration.

The Canadian government issued a security advisory related to the vulnerability found in Zbtlink routers.

Users are advised to remove affected routers from their networks and monitor for any signs of compromise.

What Happens Next

01Zbtlink is developing updates to address the backdoor vulnerability.
02Users are advised to remove affected routers from their networks.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Cybersecurity firm VulnCheck identified a backdoor in at least 20 Zbtlink router models.
Zbtlink Electronics announced it is suspending sales of affected routers and removing the software.
The company stated the backdoor was intended for technical support upon customer request.
The backdoor automatically connected to a specific IP address and Chinese-registered domain.
The Canadian government issued a security advisory related to the vulnerability.

Sources

T1
China's Zbtlink suspends sales of routers found to contain backdoorReuters

Related Stories

Thousands of servers vulnerable to backdoor exploits via motherboard controllers
5 Aug · 10:51 PM
Meta AI model breached another company during security test
5 Aug · 10:32 PM
ByteDance founder urges staff to avoid AI model distillation
6 Aug · 7:22 AM
Meta AI model breached third-party system during testing
6 Aug · 2:11 AM
Trump's Tech Ties Under Fire From Both Parties Over AI Inaction
6 Aug · 10:16 AM