Chinese Router Backdoor ENDLESSDOORS Caught Phoning Home to Beijing
VulnCheck found a deliberate backdoor in routers sold under Zbtlink and Wiflyer brands. Here's what SMBs need to check.

Researchers at VulnCheck just discovered a deliberate backdoor implanted in the firmware of routers manufactured by Shenzhen Zhibotong Electronics and sold under brand names including Zbtlink and Wiflyer. The backdoor, which VulnCheck dubbed ENDLESSDOORS, phones home to command-and-control servers in China and waits for instructions. If your business is running one of these routers, disconnect it now and replace it.
What ENDLESSDOORS Actually Does
The backdoor is built around a small open-source tool called rctl (remote control linux), uploaded to GitHub in January 2015 and never updated. The tool implements a basic command-and-control client and server. Once embedded in the router’s firmware, it connects outbound to a server on port 7000 and waits to receive shell commands or a reverse bash session.
What makes ENDLESSDOORS more dangerous than a typical vulnerability is that the router initiates the connection. There is no listening port to discover from the outside, no inbound firewall rule needed. VulnCheck’s researchers put it plainly: a unit behind three layers of firewalls in a hotel back office is just as reachable as one with a public IP, as long as it can make an outbound TCP connection to the command server.
That means standard perimeter defenses won’t flag it. The connection looks like normal outbound traffic because, from the network’s perspective, it is.
Why This Matters for SMBs
Small and mid-sized businesses are disproportionately exposed to this kind of supply chain threat. Budget routers from lesser-known brands are common in branch offices, retail locations, and warehouse operations. Many of these devices were originally manufactured by the same handful of Chinese ODMs and then rebranded for the US market. A router your ISP shipped in a box with their logo on it may well contain firmware from a manufacturer you’ve never heard of.
The US government banned the import and sale of new Chinese-made routers earlier this year, but that ban doesn’t apply to devices already deployed. If your business bought networking gear in the past few years and didn’t verify the manufacturer, now is the time.
The broader pattern here is not new. Compromised network equipment has been a recurring theme, from the TP-Link router concerns that prompted the federal ban to the Asus botnet campaign discovered in 2025. ENDLESSDOORS stands out because the backdoor is not a vulnerability being exploited. It is a feature, baked into the firmware by design.
Affected Models to Check
VulnCheck published a full list of affected model numbers. Ignore the brand name on the device and look for the actual model number, which is usually on a label on the bottom or back:
- CPE2801
- WE1026-5G-WD
- WE1326
- WE2007
- WE2008-DSIM
- WE2416
- WE3326
- WE5927
- WE5931
- WE5931AC
- WE826-T3-DSIM
- WG108
- WG1602
- WG1608-DSIM
- WG209
- WG2105
- WG2107
- WG259
- WG3526
- Z8102AX-2DSIM
If any device in your environment matches this list, take it offline immediately. There is no patch that fixes a deliberate implant.
What to Do Next
Audit your network hardware. Every router, access point, and gateway in your environment should have a documented manufacturer, model number, and firmware version. If your asset inventory doesn’t include network gear, that’s the first gap to close.
Check for outbound anomalies. If you have endpoint detection and response or a managed firewall, review outbound connection logs for sustained TCP connections to unfamiliar IP addresses on port 7000. ENDLESSDOORS-style implants rely on blending in with normal outbound traffic, so this requires active monitoring, not just a default firewall rule set.
Replace suspect devices with known-good hardware. When choosing replacements, stick with vendors whose supply chain and firmware you can verify. Enterprise-grade equipment from Fortinet, Cisco Meraki, or Aruba comes with published firmware integrity checks. Budget routers save money upfront but create exactly the kind of blind spot that ENDLESSDOORS exploits.
Treat network hardware as part of your security posture. Routers and switches often sit outside the patch management and monitoring programs that cover endpoints and servers. That gap is precisely what makes them attractive targets. A layered defense approach that extends to network infrastructure is the baseline, not the aspiration.
If your business doesn’t have the internal capacity to audit network hardware or monitor for outbound command-and-control traffic, that is exactly the kind of gap a managed cybersecurity program closes.
Not Sure What's on Your Network?
We help Texas and Oklahoma businesses audit their network infrastructure and lock down blind spots.
Get a Free AssessmentServing Businesses Across Texas & Oklahoma