Twenty Chinese Router Models Ship From The Factory With A Hidden Backdoor
Researchers at VulnCheck say every current Zbtlink firmware image contains an implant that phones home to Chinese servers and hands attackers root access.

Key points
- Security firm VulnCheck found a hidden backdoor built into 21 firmware images across 20 router models made by Chinese vendor Zbtlink.
- The implant has been present in Zbtlink firmware for more than two years.
- It starts automatically when the router boots and calls out to servers in China.
- Once active, an outside attacker gets full control of the router without needing a password.
- Zbtlink routers are sold worldwide, often under other brand names, and are common in small businesses and industrial kit.
A batch of routers built by Chinese manufacturer Zbtlink shipped from the factory with a backdoor baked into the firmware, according to research first reported by The Hacker News.
VulnCheck examined every firmware image Zbtlink currently offers for download. All 21 of them, covering at least 20 router models, contain the same implant. The oldest affected build is more than two years old. VulnCheck has been a reliable source on this beat: we've covered the firm's findings six times since 22 July 2026, including a path traversal flaw it flagged under active exploitation.
A backdoor is a secret route into a device that bypasses the normal login. This one doesn't wait to be switched on.
What does the backdoor actually do?
It gives an outside attacker root access, meaning complete control, without asking for a password. The implant runs at startup and beacons out to servers in China, waiting for instructions.
Root access on a router is about as bad as it gets. Whoever holds it can read traffic flowing through, redirect users to fake websites, plant malware on other machines, or use the router as a stepping stone into a company's internal network.
Think of it as the network equivalent of a locksmith leaving a spare key under every doormat they install and mailing the address list to a stranger.
Who makes these routers and where do they end up?
Zbtlink is a Shenzhen-based manufacturer selling 4G routers, industrial gateways and cellular Wi-Fi kit. Its hardware often turns up rebadged under other brand names, which is common in the low-cost networking market.
That means a buyer may own an affected device without ever seeing the Zbtlink name on the box. The routers appear in small offices, retail sites, vending machines and vehicles where a cheap cellular connection is handy.
Is this really new, or just old tricks in new firmware?
Honestly, it's a very old trick. Hard-coded backdoors in consumer and small-business routers have been a running theme in security research for over a decade. What's striking here is the scale and the fact that it isn't a leftover debug tool or a sloppy default password. It's a purpose-built implant that beacons out on its own, baked into every image the vendor ships.
Compare it to the classic web-security equivalent: a login page that quietly accepts a magic username no customer was ever told about. Same idea, wired into the boot process instead of a web app. Router hijacking has drawn sustained attention lately: our 13 July story found FSB Centre 16 scanning the internet for routers with weak passwords at hospitals, power firms and banks across nine countries, which is a different threat actor but the same chokepoint.
What should owners of these routers do?
If you or your employer runs a Zbtlink router, or a rebadged unit that might be one, treat it as untrusted until proven otherwise. Check the maker's name in the admin panel or on the underside of the device.
For a small business, the safest short-term move is to put the router behind a firewall you do control and block outbound connections to unknown addresses, then plan a swap to hardware from a vendor with a public security advisory process. A firmware update from Zbtlink alone won't be reassuring, given the implant has sat in every image for years.
Home users are less likely to have one directly, but anyone using a mobile hotspot or industrial gateway bought on a marketplace should check the brand.
Common questions
Can I tell if my router is affected just by looking at it?
Not easily. Check the brand and model against Zbtlink's product list, and remember that the same hardware is often sold under other names. If in doubt, ask whoever installed it.
Does resetting the router fix the backdoor?
No. A factory reset restores the firmware that contains the backdoor, so the problem comes right back. Replacing the device is the only clean fix.



