Researchers Uncover Backdoor in Chinese-Made Internet Routers | SupplyChainBrain

Researchers Uncover 'Backdoor' in Chinese-Made Internet Routers

Photo: iStock/alxpin
Photo: iStock/alxpin

Researchers are warning that more than 20 models of a Chinese-made router contain a software "backdoor" that could allow foreign access and possible connections to other devices on a network.

According to Reuters, cybersecurity firm VulnCheck says the backdoor, known as "Endlessdoors," ships in multiple models of routers made by Chinese company Zbtlink, under both Zbtlink and Wiflyer brands. VulnCheck CTO Jacob Baines estimates that at least 100,000 such routers have already been deployed globally, although it's difficult to pinpoint exactly where they are, or how many are in use in the U.S.

In an August 5 blog post, Baines explained how Endlessdoors automatically communicates to a specific IP address and Chinese-registered domain every 35 seconds. Whoever controls those domains would have the ability to take control of the router and use it to tap into other devices on that network.

"If I have it in my lab, in ⁠my lab at my university, you just invited them straight into your lab and they can roam the network as they choose," Baines said. "The capabilities are devastating."

Zptlink operates as a subsidiary of Chinese manufacturer Shenzhen Zhibotong Electronics, which builds routers and then white-labels them to be sold under other brands. Wiflyer is known as a budget brand for internet routers and mobile hotspots, selling primarily on third-party platforms like Amazon and Alibaba. 

The Federal Communications Commission banned all new foreign-made internet routers in late March. However, the ban came with several exemptions — including non-Chinese firms that still had ties to China — and any models that had been authorized by the FCC prior to March were still allowed to be imported and sold to American consumers. 

Related Content

Related Videos

Featured Product

Page 1 of 1068
Next Page

Visit Our Sponsors