In a chilling discovery that underscores the hidden dangers of the globalized electronics supply chain, security researchers have unveiled a series of sophisticated, pre-installed backdoors embedded directly into the firmware of networking hardware manufactured by Shenzhen Zhibotong Electronics (ZBT). The findings, detailed in a comprehensive report by the security firm VulnCheck, reveal that these aren’t merely accidental security flaws—they are, by design, persistent surveillance and control mechanisms that have potentially compromised thousands of routers worldwide.

The discovery centers on three distinct malicious implants: ENDLESSDOORS, DARKLANTERN, and SPEAKINGSTONE. These tools provide remote, unauthenticated, and near-total control over affected devices, granting attackers the ability to execute arbitrary commands as the root user. Because ZBT serves as an Original Design Manufacturer (ODM) for a vast array of global brands, the scope of this compromise extends far beyond devices labeled "ZBT," reaching into homes, businesses, and critical infrastructure across the globe.

The Anatomy of the Compromise

The investigation began with a routine audit of the Zbtlink AX3000 router. Researchers were alarmed to discover an implant dubbed ENDLESSDOORS, a remote-control system buried deep within the device’s firmware. Unlike traditional malware that infects a system after the fact, ENDLESSDOORS is baked into the very foundation of the router’s operating system.

ENDLESSDOORS: The Silent Root Access

ENDLESSDOORS operates by masquerading as a standard Linux kernel process called kworker. By mimicking a legitimate system task, it avoids detection by casual observers and standard monitoring tools. Upon boot, the router periodically attempts to "phone home" to a hard-coded command-and-control (C2) server.

Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different…

The security implications are catastrophic: the system lacks any form of meaningful authentication or encryption. When the router connects to the server, it awaits instructions. Any command received is executed immediately with root-level privileges, effectively granting an attacker total sovereignty over the device. This allows for the theft of sensitive data, the alteration of network traffic, or the redirection of users to malicious websites.

DARKLANTERN and SPEAKINGSTONE: The Surveillance Layer

Following the discovery of ENDLESSDOORS, VulnCheck analysts expanded their scope by purchasing an $88 "Deep Orange" branded cellular router from a US-based Amazon seller. The device, which was found to be a white-labeled ZBT-WE826-T2, contained two additional, equally alarming implants: DARKLANTERN and SPEAKINGSTONE.

DARKLANTERN acts as an open, unauthenticated listener on the router’s Wide Area Network (WAN) port. By sending a simple 19-byte data packet, an attacker can extract a comprehensive device fingerprint, including the model, firmware version, and MAC address. More critically, the backdoor’s "security" relies on a static, hard-coded salt ("mqonu.com") and a trivial MAC address filter that can be bypassed by simply providing a string of zeroes.

SPEAKINGSTONE, meanwhile, is perhaps the most sophisticated of the trio. It runs as the yunmgrd service and beacons outbound to ZBT’s infrastructure. This allows the implant to circumvent firewalls and Network Address Translation (NAT) devices, as it initiates the connection from the inside out. Once established, it provides remote operators with a full suite of espionage capabilities, including the ability to steal PPPoE credentials, perform DNS hijacking, and establish persistent reverse SSH tunnels.

Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different…

Chronology of the Investigation

The revelation of these vulnerabilities did not happen overnight. It was the result of a deliberate, methodical effort by VulnCheck to understand the integrity of budget-friendly networking hardware.

  • Early Discovery: Analysts identified anomalous behavior in the Zbtlink AX3000, leading to the identification of the ENDLESSDOORS implant.
  • Expansion of Scope: Recognizing that ZBT hardware is rebranded by dozens of companies, researchers conducted a broader analysis of secondary-market devices, leading to the purchase of the "Deep Orange" router.
  • The Sinkhole Experiment: After discovering a dormant backup domain in the malware, VulnCheck registered the domain www.findmyipaddr.com to observe the behavior of infected devices in the wild.
  • Data Aggregation: By August 21st, the researchers had logged 392 unique devices calling home to their sinkhole server. The data indicated that the overwhelming majority of these devices (390) were located in China, specifically on the China Mobile network.
  • Public Disclosure: VulnCheck officially assigned CVE-2026-66747 to the ENDLESSDOORS vulnerability, assigning it a critical CVSS score of 9.3, and released their findings to warn the public and global security community.

The Global Supply Chain Crisis

One of the most unsettling aspects of this story is the "bewildering array of brands" that sell ZBT-manufactured hardware. Because ZBT operates as an OEM/ODM, they produce the hardware, write the firmware, and then ship it to companies that slap their own logos on the plastic chassis.

Brands such as Lippert Components, Wave WiFi, OneX, MoFI Network, Digineo, and dozens of others have sold this hardware under their own names. For the consumer, this means that even if you avoid buying a "ZBT" router, you may still be inadvertently purchasing one of their devices. The research shows that this hardware platform is ubiquitous in cellular routers, travel routers, and equipment often used in RVs and remote deployments.

When questioned about these "features," ZBT has reportedly characterized the implants as "after-sales technical support mechanisms." However, security experts vehemently reject this justification. In a secure system, technical support backdoors—if they must exist—would be protected by robust, multi-factor authentication and encrypted channels. The absence of such protections suggests these were not built for legitimate troubleshooting, but rather for silent, unauthorized control.

Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different…

Implications for Security and Privacy

The implications of the ZBT firmware backdoors are profound. In an era where the home router is the primary gateway to the internet, it is the most critical piece of security infrastructure in the domestic environment. By compromising the router, an attacker effectively controls the "front door" of the user’s digital life.

The Death of Trust

The most significant impact is the erosion of trust in the supply chain. If a user cannot rely on the integrity of their networking equipment, they cannot secure their personal data, their financial transactions, or their private communications. The fact that these backdoors are installed at the factory level makes them virtually impossible to remove through standard software updates, as the malicious code is baked into the core firmware.

The Surveillance Threat

The high concentration of infected devices within China, specifically on the China Mobile network, points toward a state-sanctioned surveillance application. For residents of these regions, the routers act as persistent, invisible sensors that report data back to a central authority. For international users, the presence of these backdoors on devices sold on platforms like Amazon suggests that these tools could just as easily be repurposed for global espionage or the creation of massive, decentralized botnets.

The Difficulty of Remediation

For the average consumer, the path forward is bleak. Because the vulnerability is inherent to the firmware, there is no "patch" that can be applied to "clean" the device. VulnCheck and other cybersecurity experts emphasize that the only viable solution is to replace the device entirely.

Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different…

Conclusion: A Wake-Up Call for Hardware Integrity

The ZBT firmware scandal serves as a stark reminder that the "Internet of Things" (IoT) and the broader networking hardware market are built on a foundation of precarious trust. When consumers purchase hardware from obscure OEMs, they are often unaware of who actually wrote the code running their devices.

As the digital landscape becomes increasingly hostile, the need for transparency in firmware development has never been greater. Until hardware manufacturers are held accountable for the integrity of the code they ship, the threat of "digital Trojan horses" will remain a persistent danger to global internet users.

For now, the lesson is clear: if you are using networking hardware from an obscure, low-cost brand, you are effectively running software that you do not own and cannot control. Security is not just about strong passwords and robust firewalls; it is about the fundamental integrity of the hardware that connects us to the world. In the wake of the ZBT discovery, that foundation has been shown to be deeply cracked.

Leave a Reply

Your email address will not be published. Required fields are marked *