Cybersecurity experts have identified a hidden backdoor in at least 20 Zbtlink router models that can be accessed remotely by attackers running commands as root This article explores backdoor 20 zbtlink. . The implant dubbed ENDLESSDOORS is embedded within the firmware of these routers, starting automatically upon boot and communicating with remote command-and-control (C2) servers without requiring direct internet exposure from the device itself.

Affected equipment includes consumer, small-business, 5G, and cellular router models manufactured by Shenzhen Zhibotong Electronics, sold under the Zbtlink brand name and possibly others with white-label branding. Researchers advise organizations to identify devices using their actual model numbers rather than relying on names or logos printed on the casing, as identical hardware may have been resold under different brands such as Wiflyer.

Category Details Threat name ENDLESSDOORS CVE CVE-2026-66747 Affected vendor Zbtlink / Shenzhen Zhibotong Electronics A special command, rctlbash, can instruct the device to create an interactive root shell. This allows an operator who can control the designated C2 server, intercept traffic paths, manipulate DNS resolution, or impersonate remote endpoints could gain unrestricted access to a compromised router. Use in-browser data inspection from ANY.RUN for faster detection, investigation, and response, while gaining complete visibility into phishing activities to strengthen your SOC and reduce Mean Time To Repair (MTTR).