Chinese Router Maker Zbtlink Caught Shipping Devices With Built-In Backdoor
Cybersecurity firm VulnCheck has revealed that routers made by Chinese manufacturer Zbtlink contain a factory-installed backdoor affecting at least 20 device models. The flaw was found across all 21 firmware images currently available from the company, spanning more than two years of releases, suggesting the issue has been present for a long time rather than being a one-off mistake.
According to the report, the backdoor starts automatically when the router boots up and attempts to communicate with servers believed to be located in China. Because it grants unauthenticated root shell access, anyone aware of the backdoor could potentially take full control of an affected device without needing a password or any form of login credentials — giving attackers a powerful foothold on business and home networks alike.
While the full scope of who might exploit this backdoor and how it could be used remains unclear, the discovery raises fresh concerns about supply chain security in networking hardware, particularly devices sourced from unfamiliar or low-cost manufacturers. Small businesses that rely on budget routers for internet connectivity, VPNs, or remote access should treat this as a reminder to scrutinise the hardware behind their network infrastructure.