Root Backdoor in Zbtlink Routers: ENDLESSDOORS Enables Remote Control
Learn about ENDLESSDOORS, a backdoor in Zbtlink routers enabling remote root access. Critical risk discovered; protect your network with these indicators.
Illustrative image generated with AI
A Backdoor Embedded in the Firmware
VulnCheck identified ENDLESSDOORS in 20 Zbtlink router models, with evidence suggesting a presence across approximately two dozen devices and multiple firmware generations.
The research was published on August 7, 2026, by Pierluigi Paganini. The component was discovered by Jacob Baines while analyzing a Zbtlink AX3000 router purchased through Alibaba.
The devices are manufactured by Shenzhen Zhibotong Electronics and also marketed under the Wiflyer, ZBT, and ZBTWiFi brands. They are also sold through Amazon, Alibaba, and Shopify. The complete list of affected models has not been disclosed.
Unauthenticated Command Execution as Root
ENDLESSDOORS is automatically launched by the skworker init script. The malware creates two processes named kworker, running in user space with root privileges and deliberately resembling legitimate kernel threads.
The component uses rctl, an open-source tool published on GitHub in 2015 that appears to be no longer maintained. The router connects to servers configured in the firmware without a handshake, key exchange, negotiation, or mutual authentication.
At the beginning of the session, it sends a fixed 39-byte message consisting of a class label with null padding and the LAN MAC address. Every received command is passed to popen() and executed with UID 0, without an allowlist, sandbox, or other controls.
The string rctlbash triggers a second stage: the router connects to TCP port 7001, creates a pseudo-terminal, and attaches a /bin/sh shell to the remote server. This gives the operator an interactive root shell.
VulnCheck simulated the command-and-control server. The device connected and returned a privileged shell in less than two seconds.
Why the Risk Is Critical
Because the connection originates from the router, simply blocking inbound traffic does not protect the device. Even a device located behind multiple firewalls remains exposed if it can reach the command servers.
Control of the remote infrastructure could allow attackers to:
- modify the router’s configuration;
- intercept or alter traffic;
- use the device as an entry point into the internal network;
- incorporate it into botnet campaigns;
- maintain an interactive shell with administrative privileges.
All analyzed models communicate with four primary and secondary endpoints. Centralized control of these addresses could therefore enable commands to be sent simultaneously to multiple routers.
Indicators and Actions for Administrators
Indicators to check include:
kworkerprocesses not enclosed in parentheses;- the
skworkerstartup script; - the ENDLESSDOORS component;
- the string
rctlbash; - traffic to TCP/7001.
The reported endpoints are:
zbtctl.epplink[.]net—47.100.190[.]9647.107.224[.]89online-string[.]com—45.32.81[.]152rbdg4nzqadui[.]wikaba[.]com—43.248.136[.]125
Administrators should identify Zbtlink, Wiflyer, ZBT, and ZBTWiFi models present on their networks, monitor connections to these indicators, and assess whether they should be blocked. The source does not identify any corrective firmware, patches, or official removal procedures.
According to the reported assessment, ENDLESSDOORS appears to be a feature intentionally embedded by the manufacturer rather than an accidental defect that can be resolved through a routine update. Replacing or withdrawing the devices may therefore be necessary, particularly in enterprise networks.
Sources
This article is an original reworking based on the sources below.




