A security analysis has uncovered a clandestine backdoor known as EndlessDoors within routers produced by the Chinese manufacturer Zbtlink. These devices, also sold under the Wiflyer brand, establish periodic connections to a remote server in China to grant external operators full control over the hardware.
The 35-second heartbeat of the EndlessDoors backdoor
The technical mechanism of the EndlessDoors vulnerability is designed for stealth and persistence. according to the threat-intelligence report, the firmware on affected Zbtlink and Wiflyer routers initiates a connection to a remote server located in China every 35 seconds. If this connection is successful, it opens a privileged shell, which effectively allows a remote operator to seize total control of the router.
Because this traffic originates from inside the user's own home or corporate network, it is uniquely positioned to bypass standard firewall rules. This creates a stealthy foothold for attackers, as the router—the very device meant to secure the network—becomes the primary point of entry for unauthorized access.
How Deep Orange rebranded Zbtlink's security risk
The danger of this vulnerability is amplified by the industry practice of white-labeling, where one manufacturer produces hardware that other companies rerand and sell. As the report says, the U.S.-based firm Deep Orange sold rebranded Zbtlink routers long before the EndlessDoors backdoor was identified. This means that consumers who believed they were buying a product from a domestic firm were actually installing hardware with a built-in vulnerability linked to a Chinese server.
This rebranding strategy makes it nearly impossible for regulatory bodies to track the total number of compromised devices.. Because the same Zbtlink firmware can appear under various brand names, the footprint of the EndlessDoors vulnerability extends far beyond the Zbtlink and Wiflyer labels.
Zbtlink's 'after-sales support' justification
When confronted with these findings,Zbtlink defended the existence of the backdoor by claiming the capability was intended as a convenience for after-sales support. The company has since asserted that it immediately stopped the distribution of any firmware containing this specific vulnerability.
However, this justification does little to protect existing users. While Zbtlink may have ceased publishing the vulnerable firmware, thousands of routers installed prior to the shutdown remain active in offices and homes worldwide. For the average consumer, disabling the backdoor requires a level of technical networking skill and firmware editing that is far beyond the reach of a lay user.
A new chapter in the West's struggle with Chinese hardware
The discovery of EndlessDoors fits into a larger, ongoing geopolitical struggle regarding the security of Chinese technology. For several years, Western lawmakers have pushed to restrict Chinese applications and hardware on national security grounds, leading to high-profile restrictions on Chinese telecom giants in the United States.
While previous debates often focused on massive infrastructure or viral social media apps, the Zbtlink case highlights a more insidious threat: inexpensive, mass-produced consumer electronics.. This incident serves as a reminder that the drive for lower costs in the hardware supply chain often comes at the expense of rigorous security auditing, leaving users vulnerable to state-sponsored or criminal exploitation.
The missing retail data from Zbtlink
Despite the severity of the flaw, the actual scale of the EndlessDoors compromise remains an open question. Because no external entity has access to Zbtlink's internal retail and customer data, there is no way to verify how many units were shipped or where they are currently deployed.
Furthermore, it remains unclear whether the remote servers in China have actually been used for malicious data exfiltration or if the backdoor remained a dormant capability. The report provides evidence of the vulnerability's existence , but the full extent of the exploitation remains unverified due to the opacity of Zbtlink's distribution network.
Comments 0