Hidden Backdoor Found in Chinese-Made Zbtlink Routers


Routers made by the Chinese company Zbtlink are shipped with a built-in backdoor, according to a new report from cybersecurity firm VulnCheck.

VulnCheck examined 20 models made by Zbtlink and found an implant on each one’s firmware that automatically communicates with cloud servers in China. The backdoor could give the company access to other devices connected to the router’s network, says Jacob Baines, the chief technology officer at VulnCheck. 

“When you take your router and you plug it into your network, it tries to reach out to a server in China that can then fully control that router,” Baines said. 

The discovery is as close to a smoking gun as we’ve seen for an argument that many cybersecurity experts and lawmakers have been making for years: Routers from China can’t be trusted.

It’s a fear of implants like this that led the state of Texas to sue TP-Link, a router manufacturer founded in China but now headquartered in California, alleging in a February lawsuit that its routers are used by the Chinese government to launch cyberattacks in the US. 

It’s also why the Federal Communications Commission instituted a blanket ban on the sale of new foreign-made routers in March, although it’s since granted exemptions to several non-Chinese manufacturers. But nothing like Zbtlink’s backdoor has ever been found in TP-Link’s routers. 

“What makes this different – and I’ve never really seen it – is that this is just an implant. It just connects out. You don’t have to make the mistake of exposing it to the internet,” Baines said. 

Zbtlink routers are sold around the world ​under both the Zbtlink and Wiflyer brand names, including on platforms like Amazon. They’re primarily used in businesses rather than home networks, Baines said. He estimates that 100,000 are currently deployed around the world, but he wrote in his report that “the true affected population might be larger than the twenty models we examined.”

Baines tells me that it’s common for Chinese routers to be white-labeled, or rebranded to look like they’re from somewhere else.

“They look like they’re from South Korea or Germany, but really they were made in China by this one company,” he said. “And they could be using that firmware. We just don’t know.”

Zbtlink didn’t immediately respond to CNET’s request for comment.



Source link

  • Related Posts

    Thousands of servers can be backdoored by exploiting buggy motherboard controllers

    Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to…

    OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

    In a talk that was a last-minute addition to the Black Hat security conference in Las Vegas on Wednesday, employees from OpenAI presented new details about a recent, high-profile incident…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Manitoba repeals Hanover school board order that would deprive older students of health-care privacy

    Manitoba repeals Hanover school board order that would deprive older students of health-care privacy

    Thousands of servers can be backdoored by exploiting buggy motherboard controllers

    Thousands of servers can be backdoored by exploiting buggy motherboard controllers

    Blanche meets with 2 key Republican senators ahead of confirmation vote

    Blanche meets with 2 key Republican senators ahead of confirmation vote

    Explosive Drone Found at German Airport Used by Ukrainian Carrier

    Explosive Drone Found at German Airport Used by Ukrainian Carrier

    Toronto police announce 546 arrests, 4,033 charges from retail theft

    Why The Embraer C-390 Is The Only Western Airlifter Smaller Nations Can Actually Afford

    Why The Embraer C-390 Is The Only Western Airlifter Smaller Nations Can Actually Afford