Chinese Routers Sold Worldwide Contain Backdoors

A Global Security Scandal Erupts as Chinese Routers Sold Worldwide Found to Contain Backdoors

Shenzhen Zhibotong Electronics Co. Ltd., a 15-year-old Chinese manufacturer, has been caught planting backdoors in its white-label routers sold globally. The company’s products have been exported to over 50 countries and regions, with an estimated annual output of 3.57 million units. These routers are typically resold by other companies in various countries, including the US, Canada, Australia, Germany, and Russia.

According to research by Jacob Baines, chief technology officer at VulnCheck, ZBT’s most recent router firmware contains a root-level backdoor. Further investigation revealed that multiple backdoors have been embedded in ZBT routers dating back several years. This is not an isolated incident; rather, it appears to be a deliberate attempt by the manufacturer to compromise the security of its customers.

One such backdoor, called “EndlessDoors,” was discovered by Baines in his own home office router. Disguised as a kernel thread for ordinary system processing, EndlessDoors initiates a connection out to the Internet, bypassing firewalls and allowing command-and-control (C2) communications with an unknown domain. Whoever controlled this domain could have commanded the router with root-level privileges, spying on internet activity, stealing credentials, or using it as an entry point into the rest of the network.

The severity of this vulnerability is compounded by the fact that EndlessDoors affects dozens of router models, including those sold under ZBT’s own brand name. Further investigation revealed two other backdoors, “SpeakingStone” and “DarkLantern,” which were identified in routers from a different company, DeepOrange, a US-based reseller of ZBT technology.

The DarkLantern backdoor is particularly concerning as it allows an attacker to initiate a connection into the infected router. This can be done by sending traffic to the UDP port used by DarkLantern, which is explicitly allowed in ZBT boxes unless protected by third-party firewalls. In a three-day span, VulnCheck detected only 203 instances of the DarkLantern backdoor exposed online, with most connections originating from the US and Russia.

The implications of this discovery are far-reaching, affecting not only individual users but also organizations that rely on these routers for their network infrastructure. The sheer number of infected ZBT routers in circulation makes it a significant security threat, with countless devices potentially vulnerable to exploitation.

To mitigate this risk, it is essential for users and organizations to take immediate action. This includes updating router firmware to the latest version, using third-party firewalls to block suspicious connections, and conducting thorough network scans to identify potential vulnerabilities. In light of this discovery, it is also crucial to scrutinize the security practices of manufacturers and vendors, ensuring that they prioritize transparency and accountability in their products.

By being aware of these risks and taking proactive measures, individuals and organizations can protect themselves from the potential consequences of compromised routers. The incident serves as a stark reminder of the importance of cybersecurity vigilance in today’s interconnected world.


Source: Dark Reading — 2026-08-27