Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Overview
Cybersecurity researchers have revealed that at least 20 router models from the Chinese manufacturer Zbtlink come with a backdoor installed at the factory level. This backdoor allows unauthorized users to access the routers through an unauthenticated root shell. The issue affects all 21 firmware versions released by Zbtlink over the past two years. The backdoor is designed to activate automatically and attempts to connect to servers located in China. This poses significant security risks for users, as it can potentially allow attackers to gain control of the devices and access sensitive information.
Key Takeaways
- Affected Systems: Zbtlink routers, specifically at least 20 models with 21 firmware versions.
- Action Required: Users should avoid using affected Zbtlink router models until a patch or firmware update is provided.
- Timeline: Newly disclosed
Original Article Summary
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to beacon to Chinese
Impact
Zbtlink routers, specifically at least 20 models with 21 firmware versions.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Users should avoid using affected Zbtlink router models until a patch or firmware update is provided. Regularly check for firmware updates from the manufacturer and consider changing default passwords and settings.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.