# Factory-Installed Root Access: Zbtlink Routers Shipped With a Backdoor That Says "Hello" and Hands Over the Keys
At least 20 commercial router models from Chinese manufacturer Zbtlink have been shipping with a factory-installed implant that opens an unauthenticated root shell — no credentials, no handshake, no negotiation. Just a "hello" message every 35 seconds, and whoever answers owns the device.
VulnCheck CTO Jacob Baines published findings this week showing the implant, codenamed ENDLESSDOORS, embedded across every firmware image currently available on Zbtlink's download page — 21 images spanning more than two years of releases. This wasn't a single compromised build or a sloppy update. It was consistent, boot-persistent, and apparently deliberate.
## An 11-Year-Old GitHub Project Becomes State-Grade Hardware Malware
The technical core of ENDLESSDOORS is almost insultingly simple. It's built on rctl — remote control linux — a small command-and-control tool uploaded to GitHub on January 14, 2015, and never touched again. One person committed it, walked away, and it apparently got embedded into commercial networking hardware sold globally.
The implant starts at boot via an init.d script named skworker and runs as a userland process masquerading as a Linux kernel thread — specifically mimicking the legitimate kworker process name to blend with normal system activity. Casual inspection of the process list won't surface it. You need to know what you're looking for.
The protocol is barebones by design. The implant sends a "hello" beacon plus the device's LAN MAC address to one of four hardcoded endpoints:
| Endpoint | Resolved IP |
|---|---|
| zbtctl.epplink.net | 47.100.190.96 |
| 47.107.224.89 | (direct) |
| online-string.com | 45.32.81.152 |
| rbdg4nzqadui.wikaba.com | 43.248.136.125 |
The server can respond with individual shell commands, or trigger the rctlbash sequence: spawn a second connection on port 7001, allocate a pseudo-terminal, and launch /bin/sh. That's a live, interactive root shell over an unencrypted channel. No authentication on either end.
## The Part Most Coverage Is Getting Wrong
Everyone is framing this as China can remotely control these routers. That's accurate. But there's a more immediately dangerous implication buried in VulnCheck's writeup.
Because the protocol involves no encryption and no mutual authentication, anyone along the network path between the implant and the C2 server can intercept and inject commands. An ISP. A man-in-the-middle attacker on the same network segment. A nation-state doing BGP-level traffic interception. Whoever controls DNS resolution for rbdg4nzqadui.wikaba.com can redirect the beacon to their own server and issue commands to every Zbtlink device currently calling home.
This is not a China-exclusive backdoor. It's a backdoor anyone can walk through.
## Twenty Models. Two Years. Every Firmware Image.
The affected device list is commercially significant. These aren't budget home routers — Zbtlink's lineup includes 5G gateway hardware, industrial CPE, and multi-SIM WAN devices used in deployments where reliability and integrity matter:
CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, Z8102AX-2DSIM
The presence of ENDLESSDOORS across every available firmware image — not just a subset, not just one product line — rules out a packaging accident or a compromised build pipeline. Something intentional put this there and kept it there.
Zbtlink has acknowledged the issue obliquely. As of this writing, the firmware download page displays a holding message indicating that "security vulnerabilities" were discovered, firmware has been pulled, and engineering is working on patches. The company has not publicly confirmed the backdoor's existence or explained how it ended up in every image.
## What to Check If You're Running Zbtlink Hardware
If you have any of these devices in production, start here:
kworker processes that are actually userland (check /proc/<pid>/exe — a real kernel thread won't have a userspace binary path)/usr/sbin/kworker, /usr/lib/librctl.so, /etc/kworker.cfg, /etc/init.d/skworkerIf you find the implant, assume the device is fully compromised. Reimaging with a known-clean firmware from a verified source is the only recovery path — and given that Zbtlink has pulled all current firmware, there's currently nowhere to get a clean image. Until patched firmware ships with a verifiable hash and a clear explanation of what changed, these devices should be considered untrusted network infrastructure.
---
## HackWire Analysis
ENDLESSDOORS lands in a pattern that's been building for years, but most post-incident coverage still treats each discovery as a surprise. It shouldn't be.
The Volt Typhoon campaign — Chinese state actors living quietly inside U.S. critical infrastructure routers for years — was a warning that cheap SOHO and SMB networking hardware had become a preferred staging ground. The response was largely theoretical: advisories, guidance, the occasional congressional hearing. Hardware-level backdoors in the supply chain were discussed as a risk. Now they're documented fact, not theoretical.
What makes ENDLESSDOORS particularly significant beyond the immediate threat is the complete absence of sophistication. This is not Equation Group firmware implants. This is a 2015 GitHub project wrapped in an init script. The attackers — whoever they are — apparently didn't need sophistication. They had physical-layer access to the manufacturing process. When you control what goes on the chip before it ships, you don't need a zero-day.
The second underreported angle: DNS hijackability. Defenders focused on blocking the four IP addresses are solving half the problem. The domain-based endpoints mean that anyone who can manipulate DNS for a Zbtlink device — through a compromised DNS server, a rogue resolver on a managed network, or BGP-level redirection — can redirect beacons to their own infrastructure. ENDLESSDOORS isn't just a China access tool; it's an access tool waiting for whoever gets there first.
For enterprises doing network audits: Zbtlink hardware likely appears in managed service environments, hospitality deployments, and industrial IoT contexts where procurement decisions prioritize cost over brand provenance. Check your asset inventories and your managed customer networks. The blast radius here isn't limited to IT-managed infrastructure.
The supply chain security argument needs to stop being abstract. This is what it looks like when it fails.
— HackWire Editorial
---
## Related Coverage