A device commonly trusted to protect the entrance to home and business networks has become the centre of an international cybersecurity warning.
Zbtlink Electronics announced that it was stopping sales of affected router models and withdrawing vulnerable firmware after security researchers identified a hidden remote-control component inside the devices.
The mechanism, named “ENDLESSDOORS” by cybersecurity company VulnCheck, was found in firmware supplied with more than 20 Zbtlink routers. Some affected devices have also been distributed under the Wiflyer name and through other companies that rebrand Zbtlink equipment.
According to the researchers, the software starts automatically whenever an affected router is switched on. It operates with the highest system privileges and disguises itself using a process name resembling an ordinary part of the router’s operating system.
The routers reportedly attempt to contact a designated internet address and a China-registered domain approximately every 35 seconds. A person controlling—or successfully hijacking—those destinations could potentially issue instructions to the router.
That level of access could place more than the internet connection at risk. Because a router sits between the internet and every device on a local network, compromising it may create an opportunity to monitor traffic, change network settings or target connected computers, cameras and other equipment.
VulnCheck estimates that at least 100,000 affected routers may be operating worldwide. Establishing the exact number is difficult because the equipment is sold under different names and through multiple international online marketplaces.
Zbtlink disputed the description of the software as a malicious backdoor. The company said it was a remote-maintenance function created to help customers who granted permission for technical assistance. It also maintained that the tool had never been used to obtain unauthorised access.
However, researchers questioned why the function was concealed, operated with administrator-level authority and was implemented in a way that could allow its control infrastructure to be hijacked. A legitimate support feature, they argued, should include transparent activation, strong authentication and clear control for the device owner.
The manufacturer said it was removing vulnerable firmware from its websites, preparing security updates and suspending sales of the affected products. Canadian cybersecurity authorities also published an official advisory concerning the vulnerability.
For existing owners, changing a Wi-Fi password or restarting the router may not eliminate the danger because the remote-control software is built into the firmware. VulnCheck advised users to disconnect affected equipment from their networks and check connected systems for unusual activity.
Businesses using the routers should also review network logs, replace exposed devices and determine whether sensitive systems were accessible through the same network. Devices should not be returned to service unless trusted, independently verified firmware becomes available.
The incident demonstrates why cybersecurity cannot end with computers and smartphones. Routers, cameras and other connected devices often operate quietly for years, yet a single hidden function inside their software can create an entrance into everything connected behind them.




