This is one outlet's own report from 9to5Mac — the article as it was filed. Other outlets are covering the same event; open the full story to compare every source side by side.
See the full story · 1 sourcesThis is one outlet's own report from 9to5Mac — the article as it was filed. Other outlets are covering the same event; open the full story to compare every source side by side.
See the full story · 1 sourcesGo to the 9to5Mac home page Switch site 9to5Toys 9to5Google Logo 9to5Google Electrek Drone DJ Logo DroneDJ Space Explored About Privacy Toggle social menu Toggle dark mode Search for: Submit Toggle search form Forums Store Podcasts Apple@Work Happy Hour 9to5Mac Daily Overtime iPhone iPhone Mac Mac MacBook Pro MacBook Air iMac Mac mini Mac Studio Mac Pro iPad iPad Pro iPad Air iPad mini iPad iPadOS Watch Apple Watch Apple Watch Ultra Apple Health Apple Watch SE Vision Vision Pro visionOS Music and TV Apple Music AirPods HomePod Apple TV Guides Reviews How Tos AAPL Apple Store Apple Arcade Apple Card Apple Silicon Apple One Apple Fitness+ CarPlay Siri HomeKit Toggle dark mode Security Malware Biggest backdoor yet found in Chinese routers sold under multiple brand names Ben Lovejoy | Aug 6 2026 - 6:14 am PT 0 Comments The most blatant security backdoor yet seen in an internet router has been found in a range of models sold under multiple brand names. A firmware implant phones home to cloud servers in China to ask for instructions, and can then be remotely controlled …
Earlier this year, the US government banned the import and sale of all new models of Chinese routers, citing national security risks. It followed the discovery last year that thousands of Asus routers had been compromised by a botnet , with devices from Cisco, D-Link and Linksys also targeted.
A major challenge to avoiding these kinds of embedded malware threats is that so many Chinese-made routers are sold under different brands, sometimes with different claimed countries of origin. Additionally, many are rebadged and supplied as standard by US ISPs, so customers have literally no idea who made their router.
Cybersecurity company VulnCheck has now found an incredible and deliberate backdoor built into routers made by Shenzhen Zhibotong Electronics and sold under a variety of brands that include Zbtlink and Wiflyer. They dubbed it ENDLESSDOORS as it can be exploited in endless ways.
They are an implant, a phone-home trojan horse. Our zero-day research team named this ENDLESSDOORS. This, at its core, is a small tool called rctl (remote control linux). Uploaded to GitHub on January 14, 2015 and never touched again, this obscure repository implements a simple command and control client and server. The server listens on port 7000 for clients to connect. It can send the client individual shell commands or tell the client to spawn a reverse bash shell.
The researchers say that it poses the biggest risk yet seen because it initiates the contact with its command and control servers.
Because the device dials out, none of this requires the router to be reachable from the internet. There's no listening port to find and no inbound rule to punch through. The connection originates inside the network and traverses NAT and typical egress filtering the way any outbound TCP session does. A unit sitting behind three layers of firewall in a hotel back office is exactly as reachable as one with a public IP, provided it can get to the [command server].
VulnCheck says you should ignore whatever branding your router may have and check for one of the affected model numbers:
CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526, Z8102AX-2DSIM
If your router is one of these, you should immediately disconnect and replace it.
FTC: We use income earning auto affiliate links. More.
Check out 9to5Mac on YouTube for more Apple news:
Expand Close comments Expand Close comments Guides Security Malware Author Ben Lovejoy benlovejoy Ben Lovejoy is a British technology writer and EU Editor for 9to5Mac. He's known for his op-eds and diary pieces, exploring his experience of Apple products over time, for a more rounded review. He also writes fiction, with two technothriller novels, a couple of SF shorts and a rom-com!
AIPROPX is an independent multi-source news index — we track, compare, and connect coverage from across the web into one place you won't find anywhere else.