{"id":1126,"date":"2026-08-10T10:45:00","date_gmt":"2026-08-10T01:45:00","guid":{"rendered":"https:\/\/onepress.co.kr\/index.php\/briefing\/2026-08-10-zbtlink-endlessdoors-en\/"},"modified":"2026-08-10T10:45:00","modified_gmt":"2026-08-10T01:45:00","slug":"2026-08-10-zbtlink-endlessdoors-en","status":"publish","type":"briefing","link":"https:\/\/onepress.co.kr\/index.php\/briefing\/2026-08-10-zbtlink-endlessdoors-en\/","title":{"rendered":"Routers shipped waiting for remote orders: Zbtlink halts 20 models"},"content":{"rendered":"<p><strong>2026-08-10 10:45 KST<\/strong><\/p>\n<p>Twenty Zbtlink router models shipped with a default-enabled component capable of accepting administrator-level commands from outside the network.<\/p>\n<p>Zbtlink calls it a maintenance feature, but suspended affected sales and removed firmware downloads; this does not mean every Zbtlink router is affected.<\/p>\n<h2>What did researchers find?<\/h2>\n<p>VulnCheck says the firmware component `rctl` repeatedly contacts an outside server and waits for instructions without encryption or authentication.<\/p>\n<p>Tests showed it could run root commands and open a reverse shell, effectively giving a remote system a command window inside the router.<\/p>\n<h2>Which devices are covered?<\/h2>\n<p>The report lists 20 Zbtlink models sold through marketplaces including Amazon, AliExpress, and Alibaba. The worldwide installed base and number of real-world abuses remain unknown.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/onepress.co.kr\/wp-content\/uploads\/2026\/08\/zbtlink-endlessdoors-en.png\" alt=\"Concept image of a router communicating with a remote server beyond a firewall\" loading=\"lazy\" \/><figcaption class=\"op-briefing-image-caption\">ONEPRESS generated illustration of the remote-connection risk. It is not a photograph of an actual compromise.<\/figcaption><\/figure>\n<h2>How did the vendor respond?<\/h2>\n<p>Zbtlink said the code was intended for after-sales support rather than malicious access. It nevertheless suspended sales of affected models, removed relevant downloads, and said patched firmware is being developed.<\/p>\n<h2>What should owners check?<\/h2>\n<p>Check the maker, model, and firmware version on the label and administration page. Owners of listed models should follow the vendor update and consider replacement or strict outbound filtering until a fix is available.<\/p>\n<p>Changing only the Wi-Fi administration password does not remove an embedded firmware component.<\/p>\n<h2>Official primary sources<\/h2>\n<p><a href=\"https:\/\/www.vulncheck.com\/blog\/zbt-endlessdoors\" target=\"_blank\" rel=\"noopener noreferrer\">Primary source: VulnCheck ENDLESSDOORS research<\/a><\/p>\n<p><a href=\"https:\/\/www.zbtlink.com\/pages\/zbt-router-firmware-download-announcement\" target=\"_blank\" rel=\"noopener noreferrer\">Primary source: Zbtlink official statement<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers found a default component in 20 Zbtlink router models that can run unauthenticated root commands.<\/p>\n","protected":false},"featured_media":0,"template":"","meta":[],"class_list":["post-1126","briefing","type-briefing","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/briefing\/1126","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/briefing"}],"about":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/types\/briefing"}],"wp:attachment":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/media?parent=1126"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}