VulnCheck reported that multiple Zbtlink and white-labeled routers ship with a built-in root-level implant, dubbed ENDLESSDOORS, embedded in firmware rather than added after deployment. The implant is a customized version of the open-source rctl remote-control tool, stored as librctl.so in OpenWrt, launched automatically at boot, and disguised as a userland process named kworker. Researchers said the malware initiates outbound cleartext TCP connections to hardcoded command-and-control infrastructure on ports 7000 and 7001, with repeated callback attempts roughly every 35 seconds and no need for inbound internet exposure on the device.
The issue has been assigned CVE-2026-66747 and rated Critical, with reports stating that the command channel lacks authentication and encryption and that commands received are passed to popen() with uid 0. A reserved rctlbash function can also provide an interactive root shell, meaning any actor able to intercept the outbound path, hijack DNS or routing, or seize the fallback domain could gain unauthenticated remote code execution as root. Roughly 20 affected models have been identified, no fixed firmware is available, and defenders are being urged to inventory exposed devices, detect the implant, isolate impacted routers, or replace them.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
WaterISAC published a TLP:CLEAR alert on ENDLESSDOORS affecting Zbtlink and Wiflyer routers, stating VulnCheck confirmed the implant in 21 firmware images across more than 20 models and estimated at least 100,000 affected units globally. The alert provided detection and mitigation guidance, including process and file artifacts, hardcoded domains and IPs, and monitoring for outbound traffic on ports 7000 and 7001, while noting no fixed firmware was available.
The Canadian Centre for Cyber Security published advisory AV26-779 stating that multiple Zbtlink router models and firmware versions are affected by the ENDLESSDOORS-related vulnerability. The advisory linked to the rctl GitHub repository, VulnCheck's ENDLESSDOORS research, and Zbtlink firmware downloads, and advised users to apply updates when available.
A CVE record for ENDLESSDOORS was published, describing the embedded Zbtlink router implant as unauthenticated remote code execution as root via a hardcoded phone-home channel. The record rated the issue Critical and mapped it to CWE-506 Embedded Malicious Code.
VulnCheck reported that multiple Zbtlink and white-labeled routers ship with a built-in root-level implant it named ENDLESSDOORS, rather than being compromised after deployment. The implant masquerades as a userland "kworker" process, starts at boot, and can be abused for root command execution or an interactive root shell via its outbound C2 path.
Zbtlink publicly denied that its products contain backdoors, describing the functionality as an after-sales maintenance feature generally kept on sample units rather than mass-production devices. At the same time, the vendor posted a notice that selected firmware releases had security vulnerabilities, temporarily removed those downloads, and said it was developing and validating patched firmware.
The open-source rctl remote-control Linux tool later identified as the basis for ENDLESSDOORS was uploaded to GitHub. VulnCheck cited this repository as the origin of the customized implant found in Zbtlink firmware.
In an official statement responding to VulnCheck's August 5 report, Shenzhen Zbtlink Electronics said it immediately suspended sales of affected router models. The company also reiterated that it had removed related firmware downloads and was developing firmware updates for the rctl-related issue.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 35 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
23 references tracked. Mallory keeps watching after this page renders.
decipher.sc
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcescworld.com
Open sourcevulncheck.com
Open sourcezbtlink.com
Open sourcecisa.gov
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.