Cybersecurity researchers at VulnCheck have disclosed a factory-shipped backdoor embedded in at least 20 Zbtlink router models manufactured in China. The implant persists across 21 firmware images spanning over two years of releases, suggesting intentional inclusion rather than accidental compromise.
The backdoor grants unauthenticated root shell access to attackers. Once activated, the malicious code automatically starts and attempts to connect to command-and-control infrastructure located in China. This design allows remote actors to seize complete control of affected routers without requiring valid credentials.
Zbtlink routers, sold primarily in Asian markets but available globally through online retailers, handle critical network traffic for residential and small business users. Compromised devices become entry points for lateral network attacks, traffic interception, credential harvesting, and botnet recruitment.
The persistence across multiple firmware versions indicates the backdoor was integrated into Zbtlink's build pipeline or source code repository before deployment. This manufacturing-stage compromise affects all devices shipped with vulnerable firmware, meaning users cannot patch away the vulnerability through standard updates unless Zbtlink releases completely rebuilt versions that exclude the malicious code.
The threat extends beyond individual routers. An attacker controlling multiple Zbtlink devices gains access to a distributed network infrastructure capable of supporting command-and-control operations, data exfiltration, or launching attacks against downstream targets. Organizations purchasing these routers for branch offices or remote sites face particularly elevated risk if they lack network segmentation.
Zbtlink has not publicly confirmed the backdoor or announced remediation timelines. Users currently operating these routers should assume compromise and implement network monitoring for suspicious outbound connections to Chinese IP ranges. Organizations should isolate affected devices or replace them entirely with routers from vendors with established security practices. Network administrators should verify no unauthorized access to internal resources has occurred through these devices and review firewall logs for
