Every device on your network is something you have to trust. When you plug in a router — the box that every scrap of your internet traffic flows through — you are trusting that it does only what a router is supposed to do. A recent discovery is a stark reminder that this trust is sometimes badly misplaced, and that the danger can be built into a device before it ever leaves the factory.
Security researchers at VulnCheck reported this month that they found a hidden backdoor — which they named ENDLESSDOORS — baked into the firmware of more than 20 router models made by the Chinese manufacturer Zbtlink, also sold under the Wiflyer brand. This is not a bug. It is not a flaw someone might exploit. It is a deliberate piece of remote-control software that, by the researchers’ account, ships inside the router from the factory and quietly waits for instructions. Let’s unpack what it does, why it’s unusually serious, the manufacturer’s response, and what it means for the box humming away in your own office.
What the researchers found
According to VulnCheck’s report, the implant was present in every firmware image available on the manufacturer’s download page at the time of testing — 21 firmware versions spanning more than two years. Here is what it does, in plain terms:
- It starts the moment the router powers on. The backdoor launches at boot, automatically, with no configuration required. It is on the instant the device is.
- It phones home constantly. As often as every 35 seconds, the router reaches out to a command server across the internet, announcing itself and asking, in effect, “any orders?”
- It hides in plain sight. The malicious process disguises itself as a normal, legitimate system process, so that anyone glancing at what the router is running would see nothing obviously wrong.
- It hands over complete control, with no password. When the command server answers, the router will run whatever it’s told — including opening a live, interactive “root shell,” the deepest and most total level of control a computer can grant. And critically, there is no authentication. The researchers noted the implant simply does what the server says. There’s no lock on the backdoor at all.
The researchers traced the implant to an obscure remote-control tool that had been uploaded to a public code repository back in 2015 and never touched again — dusted off and quietly embedded into router firmware. They estimate at least 100,000 of these routers are deployed worldwide, in homes, small businesses, and offices, though they note it isn’t possible to say exactly how many are active or where.
Why this is worse than the usual router scare
We write about vulnerable routers fairly often, but this one is a different and more troubling category, for two reasons.
First, the usual advice doesn’t fully work here. Normally, when a router has a security hole, the danger is that someone reaches it over the internet, and the fix is to close off remote access, change the default password, and keep the firmware updated. But ENDLESSDOORS isn’t a door an attacker has to find from outside — it’s a process starting inside your network and reaching out. Changing your Wi-Fi password does nothing to it. A factory reset may simply reinstall the same compromised firmware. The rot is in the foundation, not the paint.
Why a compromised router is the whole ballgame: your router is the front gate that every device on your network sits behind, and through which all your traffic flows. Whoever controls it can watch where everyone goes online, redirect you to fake versions of real websites, and use your network as a launch pad to reach the computers, phones, and systems behind it. It is arguably the single worst device on your network to lose control of — which is exactly the device this backdoor lives in.
Second, and more unsettling: this is a supply-chain problem, not a mistake. The most careful person in the world — strong passwords, every update installed, remote access disabled — would still have this backdoor, because it came in the box. You cannot out-discipline a device that was compromised before you bought it. That flips the usual security model on its head: the question is no longer only “am I using this device safely?” but “can I trust where this device came from at all?”
The manufacturer’s response — and why researchers were skeptical
In fairness, we should give the manufacturer its say. Zbtlink disputed the characterization, telling one publication that the feature was “solely intended for after-sales maintenance” — essentially, a debugging tool to help support customers — and that it was generally kept only on sample units, not included in mass-production shipments.
Two things undercut that reassurance, though. The researchers reported finding the implant in every firmware image on the company’s public download page — not tucked away on a few sample units, but in the software any customer would download. And notably, the company reportedly paused its firmware downloads to address security issues shortly after the findings went public. Readers can weigh that for themselves. But “a maintenance feature with no authentication that phones home every 35 seconds and grants total remote control” is, from a security standpoint, a backdoor regardless of the intent behind it — because anyone who can reach that command channel can use it, not just the manufacturer.
The bigger lesson: your network is a supply chain of trust
Set aside this one brand for a moment, because you may well not own one of these routers. The durable lesson is bigger, and it applies to every business: every device you connect to your network is a decision to trust its maker. The router, the security cameras, the smart thermostat, the cheap network gadget someone bought online because it was $40 cheaper than the name brand — each one runs software you didn’t write, from a company you’re trusting, and each one sits on the same network as your real valuables.
Most small businesses have never once inventoried this. Nobody can say with confidence what’s connected, what brands they are, where those brands come from, or whether any of them have been quietly flagged by researchers. The gear gets bought on price, plugged in, and forgotten — which is precisely the blind spot stories like this one exploit.
Worth asking this week: What is the exact make and model of the router your business runs on — and has anyone checked whether it’s on a list like this one? * What else is connected to your network, and do you trust every manufacturer on that list? * Was any of it chosen purely on price from an unfamiliar brand? * And if a device on your network were quietly betraying you, is there anyone whose job it is to notice?
Those questions are exactly what our environment review answers. We take a clear-eyed inventory of everything connected to your network, identify the gear that carries risk — including devices flagged by security researchers — and help you understand what’s trustworthy, what should be isolated, and what needs to be replaced outright. If the make and model of your own router isn’t something you can name off the top of your head, that’s the first thing worth changing. You can’t trust a network you’ve never actually looked at — and some doors can’t be locked after the fact, only removed.
Sources: VulnCheck research (August 5, 2026); The Hacker News; Cybernews; The Register (including Zbtlink’s response); Yahoo Tech, August 2026. VulnCheck verified the implant in the firmware images it examined and demonstrated control of its own test router; it does not claim every deployed device is actively controlled. Zbtlink disputes the “backdoor” characterization.













