Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Vulnerability in Chinese-made routers from Zbtlink detected with backdoors that can be remotely accessed without authentication.
Intelligence analysis by Qwen 2.5 (3B)

Researchers found a security flaw in Chinese router models made by Zbtlink, which contain hidden backdoor implants designed to open root shells and communicate with C2 infrastructure.
Bad guys put a secret backdoor in some Chinese routers that lets them take control of your internet connection without you knowing. It's like having an invisible key to your house.
Analysis
{"
The Vulnerability Details":-1.107,"The Zbtlink routers contain a backdoor implant that starts automatically at boot and attempts to connect to C2 infrastructure every 35 seconds using the rctl tool, which is designed as a remote control system for Linux devices. This tool can send commands or spawn reverse bash shells to compromised systems.\n\n1.107, ":", -47.107.224[.]89, "," The implant uses a reserved string 'rctlbash' to open a second connection and spawn a root shell, allowing attackers to take control of the router without needing internet access.\n\n1.107, ":", -The vulnerability affects 21 firmware images spanning over two years and is embedded in all available Zbtlink routers.","
Impacted Devices":-1.107,"The backdoor implant has been found in at least 20 Chinese router models from Zbtlink, including CPE2801, WE1026-5G-WD, and WG1608-DSIM.\n\n1.107, ":", -47.107.224[.]89, "," The affected devices are configured to contact the following endpoints: zbtctl.epplink[.]net (47.100.190[.]96), 47.107.224[.]89, online-string[.]com (45.32.81[.]152), and rbdg4nzqadui.wikaba[.]com (43.248.136[.]125).\n\n1.107, ":", -The firmware downloads page on Zbtlink's website displays a message warning of potential security vulnerabilities affecting selected router firmware releases.","
Mitigation and Response":-1.107,"To mitigate the risk, users are advised to check the process list, scan for files like /usr/sbin/kworker, /usr/lib/librctl.so, /etc/kworker.cfg, and /etc/init.d/skworker, and block egress points.\n\n1.107, ":", -VulnCheck, the cybersecurity researchers who discovered this vulnerability, is working on developing and validating secured patched firmware for affected devices."}
Key points
- Zbtlink routers contain a factory-installed backdoor that opens root shells without authentication
- The backdoor can be remotely accessed using the rctl tool designed for Linux devices
- Affected models include CPE2801, WE1026-5G-WD, and WG1608-DSIM
- Users are advised to check process lists and block egress points to mitigate risk
With the help of cybersecurity researchers, users can detect and block these hidden backdoors before they cause any trouble.
If left unchecked, this vulnerability could lead to widespread network security breaches and compromise sensitive data.



