RESEARCHERS from VulnCheck have discovered a hidden backdoor in 20 router models produced by Shenzhen Zhibotong Electronics (Zbtlink). This backdoor allows remote servers to execute commands with root access, posing a significant security risk. The flaw is a built-in feature, not a patchable vulnerability, and affects routers sold under various brand names like Wiflyer, ZBT, and ZBTWiFi. The backdoor uses disguised processes that execute commands sent from hardcoded servers without any security checks.
Although Zbtlink claims the backdoor is intended for maintenance and not present in production units, there are serious concerns about this assertion, especially since multiple models are affected. Users are advised to block connections to the identified command servers and treat these devices as compromised, as no firmware fix will be available.