CRITICAL 9.3 NVD
CVE-2026-66747
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
References
- https://github.com/ycsunjane/rctl
- https://www.vulncheck.com/advisories/zbt-endlessdoors
- https://www.vulncheck.com/blog/zbt-endlessdoors
- https://www.zbtlink.com/pages/zbt-router-firmware-download
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-05 via NVD.
Risk Timeline
CVE Disclosed2026-08-05 · -1 days ago
Remediation Resources
Official Advisory
www.vulncheck.com/advisories/zbt-endlessdoorsOfficial Advisory
www.vulncheck.com/blog/zbt-endlessdoorsAnalysis & PoC
www.zbtlink.com/pages/zbt-router-firmware-download
vulnfeed aggregates 9263 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.