CVE-2026-66747

Zbtlink · CPE2801 Firmware

Multiple Zbtlink router models contain an embedded remote control implant that enables unauthenticated remote code execution with root privileges via a cleartext command channel.

Executive summary

A critical vulnerability in Zbtlink firmware exposes multiple router models to unauthenticated remote code execution through a persistent, embedded backdoor.

Vulnerability

The firmware contains an embedded malicious implant known as ENDLESSDOORS, which operates as an unauthenticated, cleartext command channel. An attacker can achieve full root-level remote code execution by intercepting or spoofing the command-and-control communication.

Business impact

Successful exploitation grants an attacker complete control over the affected network infrastructure. This allows for total data interception, lateral movement into protected internal segments, and potential permanent compromise of the hardware, resulting in significant security and operational risk. The CVSS score of 9.8 confirms the extreme severity of this flaw.

Remediation

Immediate Action: Update the affected device firmware to the latest version provided by the manufacturer. If an update is unavailable, isolate the affected devices from the internet immediately.

Proactive Monitoring: Monitor network traffic for connections to unknown external servers on ports 7000 and 7001, which are associated with the implant communication.

Compensating Controls: Implement egress filtering on network firewalls to block unauthorized outbound connections from router management interfaces to unknown or untrusted external IP addresses.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a catastrophic failure of supply chain security, as the backdoor is embedded directly into the vendor firmware. Organizations must prioritize the identification and remediation of these devices immediately, as the potential for total system compromise is absolute.