All CVEs
Vulnerability intelligence

CVE-2026-66747

Zbtlink CPE2801 Firmware CWE-506

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.7%
Riskier than 50% of all CVEs · checked 2026-09-19
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Aug 7, 2026 · latest Aug 7, 2026

Coverage timeline

Related CVEs — Zbtlink