Summary Chinese router maker suspends sales after researchers uncover security backdoor
BEIJING (Web Desk) - Chinese networking equipment manufacturer Zbtlink Electronics has suspended sales of router models found to contain a security backdoor and removed the affected firmware from its website while it develops software updates to address the vulnerability.
The move follows findings by cybersecurity firm VulnCheck, which identified the backdoor in at least 20 router models manufactured by the Shenzhen-based company. Researchers warned that the flaw could allow attackers to gain control of affected routers and potentially access other devices connected to the same network.
In a statement, Zbtlink acknowledged the findings but said the feature, named "Endlessdoors," was designed solely as an after-sales technical support tool to help customers troubleshoot and configure devices with their explicit permission.
The company insisted the tool had never been used for unauthorised access.
The discovery comes amid growing concerns in Western countries over cybersecurity risks linked to Chinese-made networking equipment. Canada also issued a security advisory this week regarding the vulnerability.
According to VulnCheck Chief Technology Officer Jacob Baines, the backdoor automatically contacted a specific IP address and a Chinese-registered domain every 35 seconds. He warned that anyone controlling or hijacking those domains could potentially take over affected routers and compromise other devices on the same network.
Baines said routers already deployed worldwide remain vulnerable and advised users to disconnect affected devices from their networks and monitor for signs of compromise until security updates become available.
He also questioned Zbtlink's explanation, saying it did not clarify why the hidden tool was difficult to identify or why it had been implemented in a manner that could be exploited by attackers.
