Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
The recent discovery of a 'factory-shipped backdoor' in Chinese router models from Zbtlink has raised significant security concerns. This backdoor, dubbed ENDLESSDOORS, is a small tool called rctl, which has been found in all 21 firmware images spanning over two years. The implant starts automatically and attempts to beacon to Chinese command-and-control (C2) infrastructure every 35 seconds, masquerading as a Linux kernel thread but running as a userland process with root privileges.
What makes this backdoor particularly insidious is its lack of authentication. Once the implant sends a 'hello' message to the server, it runs whatever command the server sends back, allowing attackers to hijack the client-server communication and obtain a live root shell. This means that anyone along the network path can control the router without being reachable from the internet.
The affected router models include CPE2801, WE1026-5G-WD, WE1326, and many others, all of which have been found to dial the same set of four primary and secondary endpoints. The list of affected models is extensive, and users are advised to check for specific files and block egress points to mitigate the risk.
This discovery highlights the importance of thorough security audits and the need for manufacturers to prioritize security in their products. It also underscores the potential risks associated with using routers from unknown or untrusted sources. As a precaution, the impacted firmware versions have been temporarily taken down from download channels, and users are advised to wait for secured patched firmware.
This incident serves as a stark reminder that even seemingly innocuous devices can pose significant security risks if not properly secured. It is crucial for users to stay vigilant and take proactive measures to protect their networks and data.