A critical vulnerability, identified as CVE-2026-66747, has been found in Zbtlink routers, specifically the CPE2801 firmware, allowing unauthenticated remote code execution with a CVSS score of 9.8. The backdoor, named ENDLESSDOORS, is built into the firmware and poses significant security risks due to its ability to run as root and communicate with a hardcoded command-and-control server. It mimics kernel processes to avoid detection and can be exploited without direct access.
Affected models encompass a variety of Zbtlink routers, with no confirmed active exploitation yet. Recommendations include blocking specific outbound traffic and assessing device trust.