VulnCheck flags outbound router implant in Zbtlink firmware
VulnCheck says it found an outbound remote-control implant in Zbtlink router firmware that phones home from deployed devices rather than waiting for an inbound attack. The research firm named the implant ENDLESSDOORS and associated it with CVE-2026-66747. Its report says affected firmware spans 20 listed router models and that there is no fixed firmware, making this a device-trust problem rather than a routine patch cycle.What VulnCheck says it found
VulnCheck says its researchers found ENDLESSDOORS in a Zbtlink AX3000 Dual SIM 5G CPE WiFi 6 router they purchased through Alibaba and tested on an isolated research network. The company describes the implant as a customized version of rctl, an old remote-control Linux tool, configured to contact external command infrastructure.The report says the implant disguises itself under a process name that resembles normal Linux kernel activity, but the observed processes were ordinary userland processes running as root. That distinction matters because it changes the finding from a suspicious process name into a privileged component embedded in the device image. VulnCheck also says the component is started at boot by a vendor firmware script, which is central to its claim that the behavior was shipped in firmware rather than added by a later compromise.
Why outbound control changes the risk
The main exposure is outbound control: according to VulnCheck, the router initiates contact with remote infrastructure, so attackers would not need to find an open management port on the public internet. A device behind NAT, typical firewall rules or several internal network layers could still reach the same control path if its outbound traffic is permitted.VulnCheck says the communications lack meaningful client or server verification and that instructions received through the channel can run with root privileges. The firm also reports that its researchers reproduced control of their test unit by intercepting the outbound communication in a lab setting, without describing a normal internet scan or a conventional inbound exploit. The practical implication is that inbound hardening alone is not enough; defenders need egress filtering, DNS visibility and router inventory, especially in branch offices, hotels, vehicles and other places where cellular CPE devices are often treated as simple connectivity appliances.
Affected models may extend beyond one logo
VulnCheck says firmware images from Zbtlink's download page contained the implant across roughly two dozen images, and it lists 20 affected models. The named models include CPE2801, WE1326, WE2008-DSIM, WG1608-DSIM, WG3526 and Z8102AX-2DSIM, among others.The report cautions buyers to match model numbers rather than rely only on the brand printed on the case. Zbtlink is described as a brand of Shenzhen Zhibotong Electronics, which also offers OEM and ODM manufacturing, and VulnCheck says the same affected hardware and firmware can appear under names such as Zbtlink, ZBT, ZBTWiFi and Wiflyer. That means procurement records, contractor-installed networking gear and unbranded cellular routers may matter as much as obvious retail purchases.
No fixed firmware is identified
VulnCheck says it did not notify Zbtlink before publication because, in its assessment, the component was embedded by the vendor's firmware build process rather than being an accidental parser flaw or a conventional externally introduced bug. The report states that coordinated disclosure is designed for unintended defects, while this finding concerns a shipped component started by the firmware itself.The firm also says there is no fixed firmware available. That is an unusual and severe position for network infrastructure owners because the normal response to a router vulnerability is to validate the model, obtain vendor firmware and patch. Here, VulnCheck frames the response as a trust decision: owners should decide whether a device that shipped with the implant can continue to carry production traffic at all.
Defensive response focuses on inventory and egress
VulnCheck's defensive guidance starts with inventory by model number. Organizations are advised in the report to check purchasing records, contractor deployments, hotel or branch office equipment, vehicle fleets and cellular CPE devices of unclear origin for the affected families.For technical validation, the report points defenders to suspicious unbracketed kworker processes, related firmware artifacts and outbound control traffic, including activity on ports 7000 and 7001 from network infrastructure segments. It also recommends alerting as well as blocking, because attempted contact can be evidence that an affected device is present. For production environments, VulnCheck's strongest recommendation is replacement, or at minimum strict egress control and segmentation with the router's LAN treated as untrusted.
Conclusion
The ENDLESSDOORS report is significant because it describes a router risk that does not depend on a newly exposed internet service or a user's misconfiguration. VulnCheck's evidence points to firmware-shipped outbound control across multiple Zbtlink-related models and brands.Until an independently verified clean firmware path exists, affected routers should be treated as suspect infrastructure. For security teams, the near-term work is practical: identify the models, look for outbound control behavior, segment exposed environments and replace devices that carry sensitive traffic.
Sources
Editorial Team - CoinBotLab