Zbtlink calls its rctl component an after sales support tool. The same week, the company paused downloads on 22 firmware builds after VulnCheck detailed an always on, unauthenticated root command and control channel.
Zbtlink, the Shenzhen router maker whose gear ships under the Zbt brand, says its firmware contains no backdoor. The same week, the company suspended downloads on 22 affected firmware versions to fix a security issue, after VulnCheck published technical details of ENDLESSDOORS, an embedded implant present in every published build.
VulnCheck researcher Jacob Baines described ENDLESSDOORS as a built-in library, librctl.so, that runs at boot as root under the process name "kworker." It opens no listening port; instead it phones a hardcoded command-and-control server over cleartext TCP, retrying every 35 seconds, with no authentication and no transport encryption. The command channel listens on port 7000 and a root shell on 7001. Any string the server returns is passed directly to popen() running as uid=0. Because the channel is unauthenticated and cleartext, any party that answers at the C2 address, occupies the network path, or acquires the hardcoded fallback domain can obtain unauthenticated remote code execution as root.
The Canadian Centre for Cyber Security issued advisory AV26-779 the same day, listing affected models including the WE and WG series, CPE2801, and ZBT-Z8102AX-2SIM.
Zbtlink's official statement describes the same component as an after-sales technical support tool that has never been used for unauthorized access, and says firmware updates are in development. The denial and the download pause, on the same product line, in the same week, are the story.