3w ago · hacker-news
Zbtlink routers are shipped with a factory-implanted backdoor named ENDLESSDOORS, which establishes unauthenticated root shells by connecting to command-and-control servers. The backdoor, based on the 'rctl' tool, runs as a disguised kernel thread with root privileges and contacts C2 infrastructure every 35 seconds. It allows remote attackers to execute arbitrary commands or spawn interactive root shells without authentication, enabling full device takeover. The backdoor is present in at least 20 router models, all of which initiate connections to a shared set of C2 endpoints.