← Back to Daily Briefing

Research has uncovered "ENDLESSDOORS," a critical supply chain compromise affecting approximately 20 Zbtlink router models distributed globally via Amazon, AliExpress, and Alibaba. Tracked as CVE-2026-66747, the vulnerability consists of a factory-installed firmware backdoor that grants remote attackers unauthenticated root shell access to the device. Because the backdoor is embedded during the manufacturing process, it provides high persistence and bypasses standard user configuration security. This allows for full administrative control over the device, enabling total network traffic interception and facilitating lateral movement within the local network environment.

  • Incident Overview: Hardware Supply Chain Compromise

    • Identified as a systemic failure in the Zbtlink manufacturing process, resulting in "born-compromised" hardware.
    • Affects roughly 20 different router models shipped with pre-installed malicious firmware.
    • Broad distribution through major global e-commerce platforms increases the attack surface across consumer and SMB environments.
  • Vulnerability Mechanics: CVE-2026-66747

    • The vulnerability utilizes a hidden entry point within the factory firmware to spawn an unauthenticated root shell.
    • This mechanism allows remote actors to execute arbitrary commands with the highest possible privileges.
    • Firmware-level integration ensures the backdoor persists across standard factory resets and user-level configuration changes.
  • Operational Impact & Risk Analysis

    • Attackers gain immediate root access without requiring any valid credentials or authentication tokens.
    • Enables comprehensive interception, mirroring, and manipulation of all network traffic traversing the gateway.
    • Provides a persistent, stealthy foothold for lateral movement into deeper internal network segments.
  • Detection & Mitigation Strategies

    • Standard software patches or configuration hardening are ineffective due to the factory-level nature of the implant.
    • Organizations must conduct immediate hardware audits to identify affected Zbtlink models within their infrastructure.
    • Recommended remediation includes the complete decommissioning of affected hardware or flashing with verified, clean, third-party firmware.
  • Strategic Implications & Conclusion

    • Highlights the critical systemic risk of relying on low-cost networking hardware with opaque supply chains.
    • Underscores the necessity of adopting Zero Trust architectures where the network gateway is not implicitly trusted.
    • Demonstrates the extreme difficulty of detecting factory-level implants using traditional endpoint or network security tools.

Related posts

  1. xploitzone.com — Zbtlink ENDLESSDOORS CVE 2026 66747 Twenty Router Models Ship Factory Installed Backdoor
  2. malware-log.hatenablog.com — Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
  3. techjacksolutions.com — ENDLESSDOORS: Factory-Installed Backdoor Across 20+ Zbtlink Routers Hands Root Shells to Anyone on the Network Path
  4. Wiu
  5. Niccs
  6. Vuldb
  7. Pcmag
  8. Cnet
  9. Thehackernews
  10. Cypro
  11. Supplychainbrain
  12. Eps
  13. Facebook
  14. Petronellatech
  15. Reddit

LINK COPIED TO CLIPBOARD