Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
| Vendor | Product | Versions |
|---|---|---|
| zbtlink | cpe2801 firmware | 22.10.09, 21.04.07, 22.02.18_1, 23.08.12, 23.08.11, 21.03.22_1, 20.09.30, 22.08.10, 22.05.31, 22.05.31, 21.12.21, 21.08.06_1, 21.07.28, 21.03.23, 23.10.11, 23.03.16, 22.05.30, 22.09.08, 22.11.01, 7.6.7.2-25.0814_114432 |