
A newly discovered hidden backdoor in Chinese-made routers has intensified global concerns over cybersecurity and supply-chain security
New Delhi: A cybersecurity investigation has uncovered a hidden backdoor in more than 20 models of Chinese-made wireless routers sold across global markets, raising fresh concerns over the security of networking equipment manufactured by Chinese companies. The discovery, announced on August 5 by cybersecurity firm VulnCheck, comes amid increasing Western scrutiny of Chinese technology products and follows a series of regulatory actions in the United States targeting foreign-made networking devices over national security concerns.
The vulnerability was identified by Jacob Baines, Chief Technology Officer at VulnCheck, who revealed in a blog post that the hidden backdoor, named “Endlessdoors,” affects routers manufactured by Shenzhen Zhibotong Electronics Co. and marketed under the Zbtlink and Wiflyer brand names. According to Baines, the flaw could potentially allow unauthorised access to devices connected to affected networks.
Routers function as the gateway between internet-connected devices and the wider internet, directing data traffic to computers, smartphones, smart televisions, surveillance cameras and numerous other connected devices. Because they control network traffic, any vulnerability in a router has the potential to expose an entire home or business network to compromise.
Baines estimates that at least 100,000 of the affected routers have already been deployed worldwide. According to his findings, the hidden backdoor automatically attempts to communicate with a fixed set of remote endpoints. Whoever controls those domains could potentially gain control of the router itself and subsequently access other devices operating on the same local network.
Explaining the seriousness of the issue, Baines noted that many users purchasing these routers for home offices or small businesses would likely have no indication that such a capability exists within the devices.
“If I have it in my lab, in my lab at my university, you just invited them straight into your lab and they can roam the network as they choose,” Baines said, describing the vulnerability as having “devastating” capabilities.
The findings add to longstanding warnings issued by several Western governments regarding cybersecurity risks associated with Chinese-made networking equipment. Authorities have repeatedly cautioned that Chinese-linked hackers have exploited routers and other internet-connected devices used in homes and small offices to establish long-term access for cyber intrusions, espionage operations and broader network compromises.
China has consistently rejected such allegations. Beijing has repeatedly denied supporting or carrying out cyberattacks or cyberespionage activities.
The VulnCheck findings emerge as US authorities continue tightening scrutiny of networking products manufactured by companies with links to China.
In March, the Federal Communications Commission (FCC) announced restrictions on imports of certain foreign-made consumer routers, citing national security concerns. In a statement issued on March 23, the FCC said foreign-made routers had been exploited by malicious actors to target American households, disrupt communications networks, conduct espionage operations and steal intellectual property.
The Commission also stated that foreign-made routers had been involved in the Volt Typhoon, Flax Typhoon and Salt Typhoon cyber campaigns targeting critical US infrastructure.
Earlier, in February, the US state of Texas filed a lawsuit against TP-Link Systems, alleging that the networking company exposed American consumers’ devices to access by the Chinese regime.
Responding to the lawsuit, TP-Link Systems, which was later spun off from its original Chinese parent company, rejected the allegations. The company stated that it would “vigorously defend” its reputation, described the accusations as “without merit,” and maintained that the Chinese Communist regime neither owns nor controls the company, its products or customer data.
The latest findings are therefore likely to add further momentum to the ongoing debate over the cybersecurity implications of networking equipment manufactured by Chinese companies and the broader supply-chain risks associated with internet infrastructure.
Alongside its technical findings, VulnCheck released the complete list of affected router models on August 5 and advised organisations to determine whether any of the identified devices remain in use within their networks.
The company emphasised that users should identify affected hardware by the specific model number rather than relying solely on the brand name. According to VulnCheck, Zbtlink manufactures routers for several other companies through Original Equipment Manufacturer (OEM) and Original Design Manufacturer (ODM) agreements, meaning identical hardware may appear under different commercial brands.
The affected router models identified by VulnCheck are CPE2801, WE1026-5G-WD, WE1326, WE2007, WE2008-DSIM, WE2416, WE3326, WE5927, WE5931, WE5931AC, WE826-T3-DSIM, WG108, WG1602, WG1608-DSIM, WG209, WG2105, WG2107, WG259, WG3526 and Z8102AX-2DSIM.
The discovery represents one of the most significant disclosures involving Chinese-manufactured wireless routers in recent months and is expected to further intensify global discussions over cybersecurity, supply-chain security and the growing scrutiny of technology products originating from China.