100K Routers Backdoored: Chinese-Made Zbtlink & Wiflyer Devices Hide 'Endlessdoors' Covert Access
VulnCheck reveals over 20 models from Shenzhen Zhibotong contain a hardcoded backdoor allowing remote control and network pivoting. An estimated 100,000 units in use globally put SMBs, home offices, and academic labs at immediate covert intrusion risk.
Key Takeaways
- VulnCheck reveals over 20 models from Shenzhen Zhibotong contain a hardcoded backdoor allowing remote control and network pivoting.
- An estimated 100,000 units in use globally put SMBs, home offices, and academic labs at immediate covert intrusion risk.
Mentioned
Key Intelligence
Key Facts
- 1VulnCheck discovered a hardcoded backdoor dubbed 'Endlessdoors' in more than 20 models of Chinese-made routers sold under the Zbtlink and Wiflyer brands.
- 2Researcher Jacob Baines estimates at least 100,000 vulnerable devices are deployed worldwide, primarily in small businesses and home offices.
- 3The backdoor automatically initiates outbound connections to a fixed set of command-and-control domains, enabling full remote router control and lateral network movement.
- 4The vulnerability allows an attacker to 'roam the network as they choose,' potentially compromising all connected devices without user knowledge.
- 5The U.S. FCC moved this year to restrict imports of foreign-made routers citing national security risks, a decision validated by this discovery.
- 6The affected routers are manufactured by Shenzhen Zhibotong Electronics Co., highlighting supply chain risks in low-cost networking hardware.
VulnCheck CTO Jacob Baines' estimate of affected devices
If I have it in my lab, in my lab at my university, you just invited them straight into your lab and they can roam the network as they choose. The capabilities are devastating.
On the real-world impact of the Endlessdoors backdoor
Who's Affected
Analysis
For security operations teams, the discovery of 'Endlessdoors' isn't just another firmware bug—it's a supply chain time bomb hidden in plain sight. The backdoor's autonomous callback to a handful of domains effectively hands attackers a persistent, unauthorized beachhead inside the network perimeter, bypassing all user awareness and traditional ingress filters. This incident demands immediate asset discovery, outbound traffic auditing, and a hard look at the procurement pipelines that allowed such hardware into sensitive environments.
Cybersecurity firm VulnCheck has uncovered a hardcoded backdoor, dubbed 'Endlessdoors,' in more than 20 models of Chinese-manufactured wireless routers sold globally under the Zbtlink and Wiflyer brands. The backdoor, found by VulnCheck Chief Technology Officer Jacob Baines, automatically initiates outbound connections to a small, fixed set of command-and-control domains. Whoever controls those endpoints can take full control of the router and, from there, pivot into connected internal networks. This discovery underscores the escalating supply chain threat posed by low-cost networking equipment with opaque firmware, affecting an estimated 100,000 devices worldwide.
Cybersecurity firm VulnCheck has uncovered a hardcoded backdoor, dubbed 'Endlessdoors,' in more than 20 models of Chinese-manufactured wireless routers sold globally under the Zbtlink and Wiflyer brands.
The affected routers are produced by Shenzhen Zhibotong Electronics Co., a manufacturer with limited transparency into its supply chain and software provenance. Baines’ research reveals that the backdoor is not a sophisticated zero-day exploit introduced by a third party but rather a deliberate, built-in mechanism that phones home without any user interaction or configuration. Once the router connects to the internet, it reaches out to a predefined set of endpoints. If an adversary controls those domains or intercepts the traffic, they gain persistent, remote administrative access. This access allows them to monitor traffic, inject malicious payloads, intercept credentials, and move laterally across the network—potentially accessing computers, smartphones, IoT devices, and sensitive data. Baines stated, 'If I have it in my lab, in my lab at my university, you just invited them straight into your lab and they can roam the network as they choose. The capabilities are devastating.'
The vulnerability sits at the intersection of consumer-grade hardware and enterprise-risk exposure. Small businesses, home offices, and even academic labs frequently purchase these affordable routers online without vetting their security posture. The backdoor’s silent operation means that network administrators and users receive no alerts or indicators of compromise. Because the outbound connection masquerades as ordinary WAN traffic, traditional firewall rules may not block it, especially if the destination domains rotate or employ encryption. This makes detection and mitigation exceptionally difficult for organizations lacking advanced network monitoring.
The geopolitical dimension is impossible to ignore. Western governments have long warned about the cybersecurity risks of Chinese networking equipment, citing potential for espionage and sabotage. This year, the U.S. Federal Communications Commission moved to restrict imports of foreign-made routers on national security grounds, a decision that gains fresh urgency from VulnCheck’s findings. While VulnCheck has not publicly attributed the backdoor to a state-sponsored actor, the deliberate inclusion of such a mechanism in mass-market hardware aligns with concerns that Chinese manufacturers could be compelled—directly or indirectly—to embed surveillance capabilities. The discovery adds to a growing body of evidence that low-cost Chinese-made IoT and networking devices frequently harbor undisclosed remote access features.
What to Watch
For cybersecurity defenders, Endlessdoors represents a critical supply chain failure. Organizations must now inventory their network edge devices to identify any Zbtlink or Wiflyer products and immediately isolate or replace them. The incident also reinforces the need for hardware bill-of-materials (HBOM) requirements and firmware integrity checks in procurement processes. Network segmentation, zero-trust architectures, and strict outbound traffic filtering can mitigate the risk, but the simplest remediation is removal of the compromised hardware. The incident will likely accelerate regulatory efforts—both in the U.S. and allied nations—to ban government and critical infrastructure use of networking gear from companies lacking transparent security auditing.
Looking ahead, the 100,000-device estimate may be conservative. VulnCheck’s enumeration is based on observed online devices, but many more could sit behind NAT gateways or in storage. The command-and-control infrastructure’s ownership remains unclear, and the possibility that the backdoor is already being exploited cannot be dismissed. Security researchers and intelligence agencies will undoubtedly pursue deeper analysis of the firmware to understand whether the backdoor was inserted at the manufacturer level, a contractor level, or via a compromised supply chain node. For now, Endlessdoors stands as a stark reminder that the network perimeter is only as secure as the least trusted device plugged into it.
Sources
Sources
Based on 2 source articles- theepochtimes.comResearcher Finds Backdoor in Chinese - Made Routers Sold WorldwideAug 5, 2026
- zerohedge.comResearcher Finds Backdoor In Chinese - Made Routers Sold WorldwideAug 6, 2026
Cite This Page
"100K Routers Backdoored: Chinese-Made Zbtlink & Wiflyer Devices Hide 'Endlessdoors' Covert Access." Cyber Intelligence Brief, August 6, 2026. https://getcyberbrief.com/story/vulncheck-uncovers-endlessdoors-backdoor-in-100000-chinese-routers
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |