Chinese networking equipment manufacturer Zbtlink Electronics announced it was suspending sales of routers found to contain a built-in backdoor and moved the affected software off its public website while it prepares software updates to remediate the issue.
Cybersecurity firm VulnCheck reported the presence of a backdoor in at least 20 models of routers produced by Shenzhen-based Zbtlink Electronics. The vulnerability was described as a component that could permit access and control of the device and, potentially, other devices on the same network.
In a statement posted to its website, Zbtlink acknowledged the research and said the mechanism identified by the researchers - which VulnCheck's chief technology officer named "Endlessdoors" - was implemented "solely as an after-sales technical support tool." The company said the support feature was intended to help customers with troubleshooting and configuration "only upon their explicit request and authorization." Zbtlink added that the tool "has never been used for unauthorized access."
VulnCheck's analysis, authored by CTO Jacob Baines, found the backdoor periodically connected to a specific IP address and a Chinese-registered domain every 35 seconds. According to that assessment, whoever controlled those remote endpoints or was able to hijack them could take control of the router and might use it to reach other devices on the same local network.
"Routers deployed around the globe are still vulnerable to hostile takeover via the backdoor," Baines wrote in his technical analysis.
Baines also noted that the vendor's explanation did not address why the support tool used a name that resisted easy identification unless someone specifically searched for it, nor why it was implemented in a way that left it exposed to hijacking.
Authorities have taken notice. The Canadian government issued a security advisory related to the vulnerability, highlighting growing concern about cybersecurity risks associated with some Chinese-manufactured networking equipment.
As for immediate user actions, VulnCheck advised that the sole mitigation available to affected router owners is to remove the devices from their networks and watch for indications of compromise while the vendor works on updates.
Zbtlink said it is developing updates to address the issue and has removed the affected software from its website during that process. Zbtlink did not immediately respond to a request for comment on Thursday.
Summary of developments
- Zbtlink suspends sales and takes down affected software while preparing fixes.
- VulnCheck identified a backdoor in at least 20 Zbtlink router models that periodically connects to external endpoints.
- Security guidance includes removing affected routers from networks and monitoring for signs of compromise.