A systemic, factory-installed backdoor affecting over 20 ZBT-Link router models has been uncovered by cybersecurity researchers, prompting urgent advice to replace the hardware and renewing scrutiny on firmware supply chain transparency.

Security firm VulnCheck detailed the findings in a report covered by The Hacker News. The malicious implant is not a subsequent vulnerability but is compiled directly into the router firmware. It was found present in all 21 firmware images publicly released by the manufacturer over more than two years, indicating a deliberate insertion during the development process.

Upon device boot, the compromised firmware activates a persistent connection to a hardcoded IP address in China and simultaneously opens an unauthenticated root shell. This configuration grants any attacker with network access complete administrative control, circumventing all standard security protocols.

The threat is particularly severe given the routers' role as network edge gateways. A compromised device allows attackers to intercept traffic, map internal networks, and pivot into connected systems. This affects both home and small-business environments where such routers often form the primary security perimeter. As of the disclosure, ZBT-Link has issued no security advisory, patch, or official guidance.

For network administrators, particularly those managing infrastructure where latency and data residency are key, the incident highlights a critical dependency. Operational assumptions about secure perimeter traffic and compliance with local data laws are undermined when edge hardware can silently beacon to external servers or expose root access. This reinforces a growing industry perspective that hardware provenance and firmware transparency must be non-negotiable in procurement policy.

In the absence of vendor fixes, the security community points to open-source firmware projects like OpenWrt as a potential path for verification and remediation. These platforms provide auditable codebases that allow administrators to control and inspect the software running on their network edges.

Significant questions remain. Researchers have not yet attributed the implant to a specific threat actor. It is also unclear whether ZBT-Link was complicit or if its development systems were breached. The full scope of deployment across enterprise and critical infrastructure is not yet known. Pending further analysis, security advisors recommend treating all ZBT-Link devices as compromised and replacing them with hardware from vendors with demonstrable security rigor.


網絡安全研究人員發現一個系統性、出廠時已安裝的後門,影響超過20款ZBT-Link路由器型號,促使業界緊急建議更換硬件,並再度引發對韌體供應鏈透明度的審視。

網絡安全公司VulnCheck於《The Hacker News》報導的研究報告中詳述了相關發現。該惡意植入物並非後續出現的漏洞,而是直接編譯到路由器韌體中。在該製造商超過兩年來公開發布的全部21個韌體映像中均發現其存在,顯示這是開發過程中蓄意植入。

設備啟動後,受影響的韌體會啟動一條連接至中國一個硬編碼IP地址的持久連接,同時開啟一個無需認證的root shell。此配置賦予任何具備網絡訪問權限的攻擊者完整的管理員控制權,繞過所有標準安全協議。

鑒於路由器作為網絡邊緣網關的角色,此威脅尤為嚴重。被入侵的設備允許攻擊者截取流量、映射內部網絡,並以此為跳板滲透連接的系統。這影響到家庭和小型企業環境,此類路由器通常構成主要的安全邊界。截至披露時,ZBT-Link尚未發布任何安全公告、補丁或官方指引。

對於網絡管理員,尤其是管理基礎設施時延和數據駐留至關重要的管理員而言,此事件凸顯了一項關鍵的依賴性。當邊緣硬件能靜默向外發送信號或暴露root訪問權限時,有關安全邊界流量及遵守本地數據法規的運營假設便受到破壞。這強化了業界一個日益普遍的觀點:硬件來源和韌體透明度在採購政策中必須是不可協商的條件。

在缺乏供應商修補方案的情況下,安全社區指出像OpenWrt這類開源韌體項目是驗證和補救的潛在途徑。這些平台提供可審計的代碼庫,讓管理員能控制及檢查其網絡邊緣運行的軟件。

仍有重要疑問待解。研究人員尚未將該植入物歸因於特定的威脅行為者。目前亦不清楚ZBT-Link是否知情不報,抑或是其開發系統遭到入侵。該後門在企業和關鍵基礎設施中的全面部署範圍尚未明確。在進一步分析之前,安全顧問建議將所有ZBT-Link設備視為已受入侵,並更換為來自具有可證明安全嚴謹性的供應商的硬件。

新聞來源 / Original News Source