Researchers discover additional backdoors in Chinese-made Zbtlink routers

Researchers discover additional backdoors in Chinese-made Zbtlink routers

More than a dozen models of Chinese-made Zbtlink routers ship with at least two backdoors that could allow for invasive remote access akin ‌to “surveillance,” according to new findings from cybersecurity firm VulnCheck. The two new backdoors — dubbed "Darklantern" and "Speakingstone" — preceded an earlier discovered backdoor called "Endlessdoors" on certain models of Zbtlink routers. The two new backdoors allow for the easy access to information about the network on which affected routers are installed as well ‌as, in the case of Speakingstone, potentially for the redirection of network traffic, representing a significant security risk, VulnCheck said in a blog post ‌detailing the new findings. The previously unreported findings come weeks after the same firm discovered and disclosed "Endlessdoors," a backdoor present in more than 20 Zbtlink routers that would have allowed anyone with access to certain domains to collect data from the routers and potentially connect to other devices on the same network. One day after VulnCheck’s disclosure, Zbtlink ⁠suspended sales ​of the routers and pulled affected software ⁠offline, and said the backdoor was actually a remote access support function and was never abused for malicious purposes.

Jacob Baines, the chief technology officer at VulnCheck who found the ⁠backdoors, said a key issue across all the implants is to alert people and organizations that they may be using infected Zbtlink routers – which are sold ​around the world under various brand names – whether they realize it or not. "Just because you’ve never heard of Zbtlink doesn’t mean it’s ⁠not being resold in other places," Baines said in an interview.

Baines called Speakingstone a "surveillance implant" in the blog post. Baines found that routers that included Speakingstone were attempting to connect to ⁠an ​unregistered domain, so he registered it himself. Information from infected routers began rolling in. The data revealed that the vast majority of the routers were active in China, suggesting that "this is domestic Chinese surveillance technology, deployed against Chinese citizens" while still being sold around the world, with ⁠the same functionality, including in the U.S.

Michael Xia, a spokesperson for Zbtlink, said in an email that the company’s products' "legitimate remote support and cloud ⁠access functions are intended solely for ⁠authorized after-sales maintenance." The remote access methods "pose no security risks, and we place the utmost importance on product security." Xia did not address questions about the alleged surveillance capabilities or respond to Baines’ contention that the company’s explanation ‌that its implants were ‌legitimate remote support tools did not make sense.

Give Feedback

Use this form for editorial or site feedback. We usually reply within 2 to 3 working days.

By submitting, you agree that we may use your email address to respond.