Skip to content

Endlessdoors Backdoor in ZBTLink Routers

alt text

Router Supply-Chain Risk Hidden Firmware Function Remote Access Exposure Potential RCE Path Network Gateway Compromise

Overview

VulnCheck researchers reported an undocumented firmware component, named Endlessdoors, in more than 20 ZBTLink router models (also sold as Wiflyer).

The functionality appears in factory firmware before deployment and periodically contacts external infrastructure, raising concern that compromised or abused control channels could enable unauthorized administrative access and network-level compromise.

Technical Specifications

Attribute Details
Issue Name Endlessdoors
Affected Vendor/Branding ZBTLink / Wiflyer
Model Scope 20+ router models
Core Behavior Hidden firmware mechanism with recurring outbound communication
Beacon Pattern Periodic callbacks (about every 35 seconds) to predefined IP/domain infrastructure
Potential Security Effect Remote command delivery pathway with possible administrative control abuse
Estimated Global Exposure 100,000+ deployed routers (reported estimate)
Exploitation Status at Disclosure No publicly confirmed active exploitation
Vendor Position Feature described as remote maintenance capability; firmware review announced

Affected Products

  • ZBTLink router models carrying affected factory firmware
  • Wiflyer-branded devices sharing the same firmware lineage
  • Organizations using affected devices as internet edge/gateway infrastructure
  • Environments where router trust is foundational for DNS, routing, and access-control policy

Attack Scenario

  1. Organization deploys vulnerable ZBTLink/Wiflyer router firmware.
  2. Device initiates periodic outbound communications to predefined external infrastructure.
  3. If that infrastructure or associated trust path is compromised/abused, attacker can push commands.
  4. Administrative control over the router is gained.
  5. Compromised gateway is used for traffic monitoring, DNS manipulation, credential theft, persistence, and pivoting into internal networks.

Impact Assessment

  • Unauthorized router-level control can alter routing, firewall, and DNS policies
  • Gateway compromise can subvert trust for all downstream client traffic
  • Attackers can establish durable control over network edge infrastructure
  • Intercepted traffic and altered DNS can expose credentials and sensitive communications
  • Router compromise can provide visibility into internal network behavior and assets
  • Supply-chain placement in baseline firmware increases stealth and pre-deployment risk
  • Misconfiguration or malicious command execution can degrade or disrupt network connectivity
  • Compromised devices may be conscripted into botnet/distributed attacks, impacting stability
  • Recovery may require firmware replacement, hard resets, and credential/policy rebuilds

Mitigation Strategies

Asset Identification and Vendor Tracking

  • Identify and inventory all ZBTLink/Wiflyer devices in production and staging.
  • Monitor vendor advisories and apply verified firmware updates as soon as trusted releases are available.

Exposure and Access Reduction

  • Restrict or disable remote management functions where not operationally required.
  • Limit administrative interfaces to trusted networks/VPN paths and hardened management endpoints.

Traffic and Configuration Monitoring

  • Monitor router outbound traffic for unexplained beaconing to unknown domains/IPs.
  • Continuously review DNS, routing, and admin configuration changes for unauthorized modifications.

Containment and Replacement Planning

  • Segment critical systems to reduce blast radius from edge-device compromise.
  • If trusted remediation firmware is unavailable, replace affected hardware with validated alternatives.
  • Maintain continuous log monitoring and IoC-driven hunting for signs of compromise.

Resources and References


Last Updated: August 6, 2026