Code Hidden In 'White-Labeled' Routers Gives Chinese Servers Full Control

Add BGR on Google:
Google Discover

The last few years have seen Western legislators repeatedly push back against Chinese apps and devices, citing national security concerns. However, while attempts to ban TikTok infamously fizzled out, major hardware manufacturers like Huawei and ZTE remain unable to sell their communications equipment in the United States. A new report from threat intelligence company VulnCheck seems to confirm what authorities have been saying for a while: Buying electronic devices made in China could pose a risk to your privacy.

VulnCheck discovered a backdoor (nicknamed EndlessDoors) in at least 20 different types of router firmware, all created by a Chinese company called Zbtlink (which also goes by Wiflyer). Simply plug in a router using the affected firmware and it'll automatically try to reach a remote server in China every 35 seconds. When successful, it opens a root terminal that allows the server's owner to take full control over the router itself. Worse still, because this is outbound traffic directly from the router, it can pass through typical firewalls.

Representatives for Zbtlink claim that this feature was designed to facilitate after-sales support and that it has immediately suspended the sale of impacted routers. Unfortunately, Zbtlink also "white-labels" its products, selling them to third-party companies and changing only the branding. Further research by VulnCheck revealed that a U.S. company called Deep Orange sold a rebranded Zbtlink router, although the tested unit predated EndlessDoors. Ultimately, the true scale of the problem is virtually impossible to find out without access to Zbtlink's customer records.

How to tell if your router is vulnerable

Even though Zbtlink no longer lets you download router firmware that contains a backdoor, an unknown number of routers still have it installed. VulnCheck found that the model number sometimes remains the same even after rebranding, but not always. If you suspect you may have purchased a compromised router, checking the model number should be your first step.

It's possible for users to prevent the backdoor from functioning. You could, for instance, block all traffic to the remote server or install different router firmware, removing the backdoor entirely. The problem is that these approaches require time, an understanding of networking, and a level of comfort tweaking router settings that most everyday consumers don't possess. Rather, the simplest solution is to outright replace your router with one from a reputable brand like Cisco, Belkin, or Netgear.

Now, just because one Chinese company included a backdoor in its hardware, it doesn't automatically mean every Chinese router is unsafe. That said, it does serve as a reminder that generic electronics may not always be as good a deal as they seem initially. In addition to all the cool things your router can do, at a basic level, it controls every webpage you see and how every device on your local network accesses the internet. With that in mind, can you really afford to take the risk?

Recommended