Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells 20%

By Ravie Lakshmanan22%

8/6/2026, 1:05:00 AM

BS Summary: This article contains 22 faulty reasoning types, including Optimism Bias, Hasty Generalization, and Negativity Bias, with Unattributed Quote as the most egregious example at 24.9% saturation with 166 hits. Analysis detected 748 faulty-reasoning hits from 666 analyzed words, generating a BS Score of 26.8% and a BS Rank of 20% (24,748 of 30,584 articles). This article is better (less manipulative) than 80.90% of the article peer group.

Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. 
According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. 
The backdoors are designed such that they start automatically and attempt to beacon to Chinese command-and-control (C2) infrastructure as often as every 35 seconds. 
They masquerade as a Linux kernel thread, but are actually userland processes running with root privileges while blending their true functionality with other legitimate kworker processes. 
The "phone home" implants have been codenamed ENDLESSDOORS. 
"ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux)," Jacob Baines, VulnCheck Chief Technology Officer, said. 
"Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server." 
"The server listens on port 7000 for clients to connect. 
It can send the client individual shell commands or tell the client to spawn a reverse bash shell." 
The "kworker" worker process running on Zbtlink AX3000, which VulnCheck analyzed, is a customized version of rctl that's configured to contact the following - 
47.107.224[.] 
89 
rbdg4nzqadui[.]wikaba[.]com 
What's more, there is no handshake, negotiation, or authentication involved. 
Once the implant sends a "hello" message to the server alongside the LAN MAC address, it's engineered to run whatever the server sends back in response. 
"One reserved string, rctlbash, tells the implant to open a second connection to port 7001, allocate a pseudo-terminal, spawn /bin/sh, and bridge it," Baines explained. 
"That is a live interactive root shell." 
"The vocabulary of this protocol is two phrases: run this as root, and give me a root shell. 
Anyone along the network path can hijack the client/server communication. 
Anyone who controls the resolution of rbdg4nzqadui.wikaba[.]com, or the address it resolves to, can control any ENDLESSDOORS implant that tries to phone home." 
An attacker can take advantage of this loophole to hijack the outbound rctl communications and obtain a live root shell, and take over control of the router without having to be reachable from the internet. 
VulnCheck noted that every firmware listed on zbtlink.com's download page embeds the rctl implant and starts it at boot with an init.d script named "skworker." 
The list of affected models is below - 
CPE2801 
WE1026-5G-WD 
WE1326 
WE2007 
WE2008-DSIM 
WE2416 
WE3326 
WE5927 
WE5931 
WE5931AC 
WE826-T3-DSIM 
WG108 
WG1602 
WG1608-DSIM 
WG209 
WG2105 
WG2107 
WG259 
WG3526 
Z8102AX-2DSIM 
Each of these models have been found to have been found to dial the same set of four primary and secondary endpoints - 
zbtctl.epplink[.]net (47.100.190[.] 
96) 
47.107.224[.] 
89 
online-string[.]com (45.32.81[.] 
152) 
rbdg4nzqadui.wikaba[.]com (43.248.136[.] 
125) 
As of writing, users visiting the firmware downloads page on Zbtlink's website are displayed the below message - 
We have detected firmware security vulnerabilities affecting selected router firmware releases. 
As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. 
Our engineering team is working intensively to develop and validate secured patched firmware. 
We will notify you immediately once the fixed, security-validated firmware is available for release. 
We apologize for the inconvenience caused. 
Thank you for your understanding. 
When contacted for comment, a spokesperson for the Chinese router manufacturer told The Hacker News that the feature is "solely intended" for after-sales maintenance and serves no other purposes. 
"It is generally retained only on sample units to assist customers with software debugging," the spokesperson added. 
"Our company specializes in OEM and ODM customization services." 
"Our customers use their own self-developed software instead of ZBT's default firmware. 
Customer security and privacy are our top priority. 
We take this report very seriously and are working to expedite the implementation of a solution." 
In the meantime, customers are advised to check the process list, scan the file system for files like /usr/sbin/kworker, /usr/lib/librctl.so, /etc/kworker.cfg, and /etc/init.d/skworker, and block the egress points. 
(The story was updated after publication to include a response from Zbtlink.) 
Article reasoning-pattern comparisonThis article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 1.6%Confirmation Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.1%The Hacker News: 1.0%Anchoring Bias0.0%This article: 3.8%Ravie Lakshmanan: 2.1%The Hacker News: 2.8%Availability Heuristic3.8%This article: 0.0%Ravie Lakshmanan: 1.1%The Hacker News: 1.1%Representativeness Heuristic0.0%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Hindsight Bias0.0%This article: 5.0%Ravie Lakshmanan: 1.7%The Hacker News: 2.2%Overconfidence Bias5.0%This article: 2.9%Ravie Lakshmanan: 2.0%The Hacker News: 2.1%Framing Effect2.9%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.8%Loss Aversion0.0%This article: 2.4%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Status Quo Bias2.4%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 9.0%Ravie Lakshmanan: 1.3%The Hacker News: 1.1%Optimism Bias9.0%This article: 5.3%Ravie Lakshmanan: 1.2%The Hacker News: 1.3%Pessimism Bias5.3%This article: 7.1%Ravie Lakshmanan: 5.7%The Hacker News: 5.3%Negativity Bias7.1%This article: 3.5%Ravie Lakshmanan: 0.5%The Hacker News: 0.7%Self-Serving Bias3.5%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.3%Fundamental Attribution Error0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Actor-Observer Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%In-Group Bias0.0%This article: 4.4%Ravie Lakshmanan: 0.8%The Hacker News: 0.3%Out-Group Homogeneity Bias4.4%This article: 1.2%Ravie Lakshmanan: 0.3%The Hacker News: 0.4%Halo Effect1.2%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 1.8%Ravie Lakshmanan: 1.6%The Hacker News: 1.3%Recency Bias1.8%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.2%Primacy Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 5.7%Ravie Lakshmanan: 3.0%The Hacker News: 3.1%Appeal to Authority5.7%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 1.1%False Dilemma0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.4%Slippery Slope0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Circular Reasoning0.0%This article: 7.2%Ravie Lakshmanan: 3.0%The Hacker News: 3.3%Hasty Generalization7.2%This article: 1.8%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Red Herring1.8%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Bandwagon0.0%This article: 5.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.9%Appeal to Emotion5.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.3%Begging the Question0.0%This article: 5.3%Ravie Lakshmanan: 1.4%The Hacker News: 1.5%Post Hoc (False Cause)5.3%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Burden of Proof0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.7%Anecdotal0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 0.6%Ravie Lakshmanan: 2.1%The Hacker News: 1.7%Ambiguity (Equivocation)0.6%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 2.6%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Special Pleading2.6%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 24.9%Ravie Lakshmanan: 2.4%The Hacker News: 1.2%Unattributed Quote24.9%This article: 3.0%Ravie Lakshmanan: 1.6%The Hacker News: 0.8%Quote-first Misdirection3.0%This article: 6.0%Ravie Lakshmanan: 1.6%The Hacker News: 1.7%Biased Writer Voice6.0%This article: 4.2%Ravie Lakshmanan: 1.6%The Hacker News: 3.2%Indoctrination4.2%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 2.6%Attempt to Sell a Product or S…0.0%

666 words analyzed.

Speakers

2speakers19%attributed speech541writer words
Selected voice

VulnCheck

100%flagged-word coverage
50 attributed words40% of attributed speech85% writer coverage
0%17.5%35.0%Unattributed Quote-30.7 ptsWriter: 30.7%VulnCheck: 0.0%0.0%Biased Writer Voice-7.4 ptsWriter: 7.4%VulnCheck: 0.0%0.0%Indoctrination-5.2 ptsWriter: 5.2%VulnCheck: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.