Twenty Chinese Router Models Ship From The Factory With A Hidden Backdoor

Researchers at VulnCheck say every current Zbtlink firmware image contains an implant that phones home to Chinese servers and hands attackers root access.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial aerial view of a vast network of illuminated fiber-optic cables converging on a central node that has gone dark, surrounding nodes stil
Share

Key points

  • Security firm VulnCheck found a hidden backdoor built into 21 firmware images across 20 router models made by Chinese vendor Zbtlink.
  • The backdoor has been present in Zbtlink firmware for more than two years, according to the researchers.
  • The implant starts automatically when the router boots and tries to call out to servers in China.
  • Once active, it can give an outside attacker full control of the router without needing a password.
  • Zbtlink routers are sold worldwide, often rebadged, and are common in small businesses and industrial kit.

A batch of routers built by Chinese manufacturer Zbtlink shipped from the factory with a backdoor baked into the firmware, according to research first reported by The Hacker News.

The finding comes from VulnCheck, which examined every firmware image Zbtlink currently offers for download. All 21 of them, covering at least 20 router models, contain the same implant. The oldest affected build is more than two years old.

A backdoor, in plain terms, is a secret way into a device that bypasses the normal login. This one does not wait to be switched on. It starts the moment the router boots.

What does the backdoor actually do?

It gives an outside attacker root access to the router, meaning complete control, without asking for a password. The implant runs automatically at startup and beacons out to servers in China, checking in and waiting for instructions.

Root access on a router is about as bad as it gets for a network device. Whoever holds it can read the traffic flowing through, redirect users to fake websites, plant more malware on other machines, or quietly use the router as a stepping stone into a company's internal network.

Think of it as the network equivalent of a locksmith leaving a spare key under every doormat they install, and mailing the address list to a stranger.

Who makes these routers and where do they end up?

Zbtlink is a Shenzhen-based manufacturer that sells 4G and 5G routers, industrial gateways and Wi-Fi kit. Its hardware often turns up rebadged under other brand names, which is common in the low-cost networking market.

That means a buyer may own an affected device without ever seeing the Zbtlink name on the box. The routers are popular in small offices, retail sites, vending machines, kiosks, buses and other spots where a cheap cellular router is handy.

Is this really new, or just old tricks in new firmware?

Honestly, it is a very old trick. Hard-coded backdoors in consumer and small-business routers have been a running theme in security research for over a decade. What is striking here is the scale and the fact that it is not a leftover debug tool or a sloppy default password. It is a purpose-built implant that beacons out on its own.

Compare it to the classic web-security equivalent: a login page that quietly accepts a magic username no customer was ever told about. Same idea, just wired into a router's boot process instead of a web app.

What should owners of these routers do?

If you or your employer runs a Zbtlink router, or a rebadged unit that might be one, treat it as untrusted until proven otherwise. Check the maker's name in the admin panel or on the underside of the device.

For a small business, the safest short-term move is to put the router behind a firewall you do control, block outbound connections to unknown addresses, and plan a swap to hardware from a vendor with a public security advisory process. A firmware update from Zbtlink alone will not be reassuring here, given the implant has sat in every image for years.

Home users are less likely to have one of these directly, but anyone using a mobile hotspot or industrial gateway bought on a marketplace should check the brand.

Common questions

Can I tell if my router is affected just by looking at it?

Not easily. Check the brand and model against Zbtlink's product list, and remember that the same hardware is often sold under other names. If in doubt, ask whoever installed it.

Does resetting the router fix the backdoor?

No. A factory reset restores the firmware that contains the backdoor, so the problem comes right back. Replacing the device is the only clean fix.

© 2026 Threat Vectr