본문으로 이동
ONEPRESS

WORLD NEWS

Routers shipped waiting for remote orders: Zbtlink halts 20 models

Global briefing
Briefings by language

Twenty Zbtlink router models shipped with a default-enabled component capable of accepting administrator-level commands from outside the network.

Zbtlink calls it a maintenance feature, but suspended affected sales and removed firmware downloads; this does not mean every Zbtlink router is affected.

What did researchers find?

VulnCheck says the firmware component `rctl` repeatedly contacts an outside server and waits for instructions without encryption or authentication.

Tests showed it could run root commands and open a reverse shell, effectively giving a remote system a command window inside the router.

Which devices are covered?

The report lists 20 Zbtlink models sold through marketplaces including Amazon, AliExpress, and Alibaba. The worldwide installed base and number of real-world abuses remain unknown.

Concept image of a router communicating with a remote server beyond a firewall
ONEPRESS generated illustration of the remote-connection risk. It is not a photograph of an actual compromise.

How did the vendor respond?

Zbtlink said the code was intended for after-sales support rather than malicious access. It nevertheless suspended sales of affected models, removed relevant downloads, and said patched firmware is being developed.

What should owners check?

Check the maker, model, and firmware version on the label and administration page. Owners of listed models should follow the vendor update and consider replacement or strict outbound filtering until a fix is available.

Changing only the Wi-Fi administration password does not remove an embedded firmware component.

Official primary sources

Primary source: VulnCheck ENDLESSDOORS research

Primary source: Zbtlink official statement