A recent investigation has exposed a critical security vulnerability in certain China-made ZBT routers, which have been shipping with two implants that grant unauthenticated attackers root access. This alarming discovery affects thousands of users worldwide who rely on these routers for their internet connectivity.
The issue lies in the design of the ZBT routers’ firmware, which includes two separate backdoors – dubbed “TinyTina” and “XMRig” – that allow hackers to remotely access the device’s root privileges without authentication. This means that an attacker can gain complete control over the router and potentially spread malware or intercept sensitive data. The TinyTina implant appears to be a cryptocurrency miner, while XMRig is a tool used for monero mining.
The affected ZBT routers are widely distributed in various regions, including Asia, Europe, and North America. Users who have purchased these devices may be unaware of the security risk they pose, as the implants are not explicitly listed in the router’s documentation or marketing materials. The ZBT routers’ firmware is designed to automatically update itself, which could potentially introduce additional vulnerabilities.
The presence of these backdoors raises significant concerns about the security and integrity of IoT devices. With millions of connected devices worldwide, the potential for catastrophic consequences due to a single vulnerability cannot be overstated. Furthermore, this incident highlights the risks associated with importing or purchasing low-cost, third-party electronics from unverified manufacturers. The compromised routers’ firmware is likely to remain vulnerable unless users take immediate action.
To mitigate this risk, ZBT router owners should immediately disconnect their devices from the internet and consider replacing them with secure alternatives. Additionally, it is essential for manufacturers to prioritize security in their design and development processes, ensuring that their products meet industry standards and are free from known vulnerabilities. In this case, the lack of transparency and oversight has put thousands of users at risk – a stark reminder of the importance of vigilance in the age of IoT devices.
In light of this incident, we recommend that all router owners review their security settings regularly and consider implementing additional protection measures, such as using VPNs or updating their firmware to the latest secure version.
Source: The Hacker News — 2026-08-28