Оксана СтепураHot News
28 August 2026, 14:40
2026-08-28
Researchers have found three backdoors in ZBT routers, which are sold worldwide under other brands. How dangerous are they?
Cybersecurity researchers at VulnCheck have found several backdoors in the firmware of routers from the Chinese company Shenzhen Zhibotong Electronics, or ZBT. The company manufactures devices that are then sold around the world under other brands. So the owner of such a router may not even know who actually manufactured it. They also found one of the infected devices in Ukraine.
Cybersecurity researchers at VulnCheck have found several backdoors in the firmware of routers from the Chinese company Shenzhen Zhibotong Electronics, or ZBT. The company manufactures devices that are then sold around the world under other brands. So the owner of such a router may not even know who actually manufactured it. They also found one of the infected devices in Ukraine.
The researchers first found the ENDLESSDOORS backdoor. It automatically starts with the router, disguises itself as a regular system process, and establishes a connection to the control server.
The server operator can then execute commands on the router with root privileges — that is, with virtually the maximum level of access to the system. According to VulnCheck, this potentially allows them to monitor traffic, steal credentials, or use the router as an entry point to other devices on the network.
And then VulnCheck CTO Jacob Baines ordered another router on Amazon — now under the Deep Orange brand. It turned out that it was actually the ZBT model, only with a different name. ENDLESSDOORS was not in the old firmware, but two more backdoors were found inside — DARKLANTERN and SPEAKINGSTONE. VulnCheck considers them to be early versions of the same remote access mechanism.
DARKLANTERN allows commands to be sent to the router over the Internet. It receives them on UDP port 9992, which is not blocked by the router's firewall. The backdoor is supposed to check the received commands before executing them, but researchers have found that these checks are easy to bypass. As a result, an unauthorized user can execute arbitrary commands on the device with root privileges.
But SPEAKINGSTONE works differently. The router itself regularly contacts the management server. Along with the request, it can transmit the device model and firmware version, MAC address, Wi-Fi network name, local IP address, operating time and even GPS coordinates. In response, the server can send it commands. Among the possibilities are changing DNS, obtaining PPPoE data and opening a reverse SSH tunnel. This makes it possible to create a channel for remote access to the device.
In addition, one of the backup SPEAKINGSTONE control domains turned out to be unregistered, so VulnCheck bought it itself. On it, the researchers launched their own server, to which routers with a backdoor began to automatically connect instead of the control server. 392 routers connected to it.
It’s much harder to figure out how many of these devices are actually operating in the world. ZBT manufactures the equipment, and other companies slap their logos on it and sell it as their own product. The researchers tracked ZBT equipment in the United States, Canada, Australia, the Philippines, Germany, and other countries. They named WiFlyer, Deep Orange, KuWFi, and CroSkylink among the brands and vendors that used the company’s platforms.
But this does not mean that every ZBT-based router has a backdoor. Some vendors install their own firmware. For example, no such components were found in the Canadian MOFI device tested by VulnCheck.
After VulnCheck was first published, Zbtlink temporarily stopped selling some routers and removed the corresponding firmware from its website. The company explained that the remote access feature was created for technical support and should only be used with the customer's permission.
Previously, dev.ua wrote that hackers linked to China had seized more than 50,000 Asus routers around the world, including in Ukraine, and used them as a hidden infrastructure for cyberespionage.
Russians hacked Ukrainians' home and office Wi-Fi routers and used them to intercept passwords and emails. SBU, FBI, and EU counterintelligence hacked GRU network
Як ламають відео-ігри та викладають їхні піратські копії? Розповідає програміст
Що, юний хакер, тобі цікаво, які ігри ще досі не крякнули? Тоді мерщій читай цю статтю. Нижче ми розглянемо, які технології використовуються для захисту ігор від злому. Також не пройдемо повз рекордсменів. Дізнаємося про рекордний час, за який вдалося зламати гру. Та розглянемо справжніх «міцних горішків».