Executive Summary
In August 2026, cybersecurity researchers uncovered a factory-implanted backdoor, dubbed 'ENDLESSDOORS,' in at least 20 router models from Chinese manufacturer Zbtlink. This backdoor, present in all 21 firmware images available over the past two years, automatically initiates and attempts to communicate with command-and-control servers every 35 seconds. Masquerading as legitimate Linux kernel threads, these userland processes run with root privileges, allowing unauthorized remote control of the devices. The backdoor utilizes a tool called 'rctl' to establish connections without authentication, enabling attackers to execute arbitrary commands or spawn interactive root shells remotely. The affected models include CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, and Z8102AX-2DSIM. This discovery underscores the critical risks associated with supply chain vulnerabilities in networking hardware, particularly those manufactured overseas. The incident has prompted heightened scrutiny of foreign-made networking equipment and reinforces the importance of rigorous security assessments in the procurement process.
Why This Matters Now
The discovery of the 'ENDLESSDOORS' backdoor in Zbtlink routers highlights the urgent need for organizations to reassess the security of their networking hardware, especially devices sourced from foreign manufacturers. This incident serves as a stark reminder of the potential risks embedded within supply chains and the necessity for comprehensive security evaluations to prevent unauthorized access and data breaches.
Attack Path Analysis
Attackers exploited a factory-implanted backdoor in Zbtlink routers to gain unauthorized root access. This backdoor allowed them to escalate privileges and establish persistent control over the devices. Subsequently, they moved laterally within the network, compromising additional systems. The backdoor's design enabled continuous communication with command and control servers. Attackers could exfiltrate sensitive data through the compromised routers. The attack resulted in significant disruption and potential data breaches.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited a factory-implanted backdoor in Zbtlink routers to gain unauthorized root access.
MITRE ATT&CK® Techniques
Socket Filters
Port Knocking
Proxy
Protocol Tunneling
System Network Configuration Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Chinese-made Zbtlink router backdoors enable unauthorized root access, compromising network infrastructure critical for telecommunications operations and customer data protection.
Internet
Supply chain attacks on routers create persistent backdoors allowing command-and-control access, threatening internet service providers' network security and customer privacy.
Information Technology/IT
Factory-shipped backdoors in network equipment expose IT infrastructure to lateral movement and privilege escalation, violating zero trust principles and compliance requirements.
Government Administration
Router backdoors beaconing to Chinese infrastructure present national security risks, enabling foreign surveillance and potential disruption of government network operations.
Sources
- Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shellshttps://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.htmlVerified
- Zbtlink Router Firmware Download Announcementhttps://www.zbtlink.com/pages/zbt-router-firmware-download-announcementVerified
- Zbtlink Routers Contain Factory-Shipped Backdoorhttps://www.vulncheck.com/blog/zbt-endlessdoorsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial unauthorized access via hardware backdoors, it could limit the attacker's ability to exploit this access to reach other network segments.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to leverage escalated privileges to access other systems or sensitive data.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could significantly reduce the attacker's ability to move laterally and compromise additional systems.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could limit the attacker's ability to maintain persistent command and control communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could reduce the attacker's ability to exfiltrate sensitive data through compromised routers.
While Aviatrix Zero Trust CNSF may not prevent all disruptions, it could limit the scope of data breaches by containing the attacker's access to a minimal blast radius.
Impact at a Glance
Affected Business Functions
- Network Security
- Data Privacy
- Customer Trust
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of sensitive customer data and internal communications due to unauthorized access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy East-West Traffic Security controls to monitor and control internal traffic flows.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous communications.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Regularly update and patch firmware to mitigate known vulnerabilities.



