Hidden Backdoor Found in Chinese-Made Zbtlink Routers

Hidden Backdoor Found in Chinese-Made Zbtlink Routers

Routers made by the Chinese company Zbtlink are shipped with a built-in backdoor, according to a new report from cybersecurity firm VulnCheck.

VulnCheck examined 20 models made by Zbtlink and found an implant on each one’s firmware that automatically communicates with cloud servers in China. The backdoor could give the company access to other devices connected to the router’s network, says Jacob Baines, the chief technology officer at VulnCheck. 

“When you take your router and you plug it into your network, it tries to reach out to a server in China that can then fully control that router,” Baines said. 

The discovery is as close to a smoking gun as we’ve seen for an argument that many cybersecurity experts and lawmakers have been making for years: Routers from China can’t be trusted.

It’s a fear of implants like this that led the state of Texas to sue TP-Link, a router manufacturer founded in China but now headquartered in California, alleging in a February lawsuit that its routers are used by the Chinese government to launch cyberattacks in the US. 

It’s also why the Federal Communications Commission instituted a blanket ban on the sale of new foreign-made routers in March, although it’s since granted exemptions to several non-Chinese manufacturers. But nothing like Zbtlink’s backdoor has ever been found in TP-Link’s routers. 

“What makes this different – and I’ve never really seen it – is that this is just an implant. It just connects out. You don’t have to make the mistake of exposing it to the internet,” Baines said. 

Zbtlink routers are sold around the world ​under both the Zbtlink and Wiflyer brand names, including on platforms like Amazon. They’re primarily used in businesses rather than home networks, Baines said. He estimates that 100,000 are currently deployed around the world, but he wrote in his report that “the true affected population might be larger than the twenty models we examined.”

Baines tells me that it’s common for Chinese routers to be white-labeled, or rebranded to look like they’re from somewhere else.

“They look like they’re from South Korea or Germany, but really they were made in China by this one company,” he said. “And they could be using that firmware. We just don’t know.”

Zbtlink didn’t immediately respond to CNET’s request for comment.

Joe Supan

Joe Supan is a senior writer for CNET covering home technology, broadband, and moving. Prior to joining CNET, Joe led MyMove's moving coverage and reported on broadband policy, the digital divide, and privacy issues for the broadband marketplace Allconnect. He has been featured as a guest columnist on Broadband Breakfast, and his work has been referenced by the Los Angeles Times, Forbes, National Geographic, Yahoo! Finance and more.

Sponsor
Sponsor
Upgrade to Pro
Choose the Plan That's Right for You
Sponsor
Sponsor
Zoekertjes
Read More
Download the Telestraw App!
Download on the App Store Get it on Google Play
×