Cybersecurity company VulnCheck said on Aug. 5 that it has found that more than 20 models of a Chinese-made wireless router sold worldwide contain a hidden backdoor that could allow unauthorized access to devices connected to the network.
The finding adds to growing Western concerns about cybersecurity risks posed by Chinese-made networking equipment. Western governments have warned for years about hackers exploiting such devices, and U.S. regulators moved this year to restrict imports of foreign-made routers.
Jacob Baines, chief technology officer at VulnCheck, who found the backdoor, said in a blog post that the vulnerability, dubbed “Endlessdoors,” affects routers manufactured by Shenzhen Zhibotong Electronics Co. and sold under the Zbtlink and Wiflyer brand names.
Routers serve as the gateway between internet-connected devices and the wider internet, directing traffic to computers, smartphones, smart televisions, cameras, and other connected equipment. Because routers manage internet traffic between connected devices and the wider internet, vulnerabilities affecting them can expose entire home or business networks.
Baines estimates that at least 100,000 such routers are deployed worldwide. The backdoor Baines discovered automatically “dials the same tiny set of endpoints,” Baines said in a blog post on the company’s website. Whoever controls those domains could take control of the router and potentially use it to access other devices on the same network, he said.
Baines said most people who order this router and use it for their small business or home office would likely have no clue that it could allow this sort of access.
“If I have it in my lab, in my lab at my university, you just invited them straight into your lab and they can roam the network as they choose,” Baines said. “The capabilities are devastating.”
Western governments have warned about Chinese-linked hackers abusing small office and home office routers and other internet devices to gain access to networks for later intrusions as well as cyberespionage.
Beijing regularly denies condoning or carrying out cyberattacks or cyberespionage.
The Epoch Times reached out to Shenzhen Zhibotong Electronics/Zbtlink for comment but didn’t receive a response by publication time.
US Scrutiny
The findings come as U.S. officials continue to increase scrutiny of networking equipment manufactured by companies with links to China.
The FCC said in a March 23 statement that foreign-made routers had been exploited by malicious actors to target U.S. households, disrupt networks, conduct espionage, and steal intellectual property.

“Foreign-made routers were also involved in the Volt, Flax, and Salt Typhoon cyberattacks targeting vital U.S. infrastructure,” it added.
In response to the lawsuit, TP-Link Systems, which was spun off from a Chinese company, said it would “vigorously defend” its reputation, called the allegations “without merit,” and added that the Chinese communist regime has no form of ownership or control over the company, its products, or user data.
Risk for Networks
VulnCheck on Wednesday published a list of 20 affected models and urged organizations to determine whether any remain deployed in their networks.
VulnCheck said users should identify affected devices by their model numbers rather than the brand name because Zbtlink manufactures routers for other companies under original equipment manufacturer (OEM) and original design manufacturer (ODM) agreements.
The company recommended replacing affected devices where possible, restricting remote management access, and installing firmware updates if security fixes become available.
The affected models, according to VulnCheck, are: CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, Z8102AX-2DSIM.







