- This topic has 0 replies, 1 voice, and was last updated 1 month ago by
Phillip Beall (W5EBC).
-
AuthorPosts
-
August 8, 2026 at 2:45 pm #49278
All,
I ran across this article and thought it was worth sharing, particularly given how much of our amateur radio equipment now depends on Internet-connected networks, remote access, hotspots, Raspberry Pis, digital-mode systems, cameras, and other networked devices.
Cybersecurity researchers at VulnCheck are reporting that at least 20 router models manufactured by Chinese company Zbtlink, including products sold under the Zbtlink and Wiflyer names, contain what the researchers describe as a factory-installed backdoor dubbed “ENDLESSDOORS.”
According to the researchers, the software automatically attempts to contact command-and-control infrastructure over the Internet and can provide remote command execution with root-level privileges. One particularly concerning aspect is that the router reportedly checks in with the remote infrastructure as often as every 35 seconds.
VulnCheck estimates that at least 100,000 of these routers may be deployed worldwide, although the actual number and geographic distribution are difficult to determine.
Zbtlink disputes the characterization that this is an intentional backdoor. The company says the functionality was intended for after-sales debugging and was associated with sample devices rather than mass-production units. However, following the report, Zbtlink removed affected firmware downloads while it investigates and prepares updated firmware.
Why might this matter to us as amateur radio operators?
A router is effectively the front door to everything on your local network. If someone gains root-level control of it, changing the password on your PC or radio isn’t necessarily going to solve the problem. Potentially exposed equipment could include shack computers, Raspberry Pis, AllStar/Echolink nodes, hotspots, SDR systems, cameras, NAS devices, remote station controllers, and anything else sharing that network.
This is also a good reminder that when we buy inexpensive networking equipment for a shack, portable setup, repeater site, or EmComm deployment, the security and update history of the manufacturer deserves consideration along with price and features.
If you own a Zbtlink or Wiflyer router, I would suggest checking the exact model and firmware version and following developments closely. Personally, I would be very reluctant to put one of the reportedly affected devices between the Internet and anything important until the situation is fully resolved.
MSN article:
Hidden Backdoor Found in Chinese-Made Zbtlink RoutersDefinitely an interesting example of why network security is becoming increasingly relevant to amateur radio.
73
Phillip Beall (W5EBC) -
AuthorPosts
- You must be logged in to reply to this topic.