
Chinese Zbtlink Routers Found Shipping with Pre-Installed Backdoor Granting Root Access
CybersecuritySupplyChainRisksBackdoorsRouterVulnerabilities
Cybersecurity researchers at VulnCheck identified a factory-shipped backdoor in at least 20 router models manufactured by Chinese vendor Zbtlink. The backdoor is embedded in all 21 firmware images available from the company over the past two years, automatically executing and attempting to establish communication with external servers in China. The implant grants unauthenticated root shell access, enabling full control over affected devices without user interaction. No specific CVE IDs, exploitation timelines, or exact model numbers were disclosed in the report. The discovery highlights a supply-chain security risk for organizations deploying these routers.