Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Security Researcher Finds Hidden Backdoor in Chinese-Made Routers Sold Under Zbtlink, Wiflyer Brands

A cybersecurity researcher has found a hidden backdoor built into more than 20 models of a Chinese-made wireless router sold around the world, according to VulnCheck, the company that discovered the flaw.
Jacob Baines, chief technology officer at VulnCheck, disclosed the vulnerability on Aug. 5 in a company blog post. He dubbed it "Endlessdoors." It affects routers manufactured by Shenzhen Zhibotong Electronics Co. and sold under the Zbtlink and Wiflyer brand names.
Baines said the backdoor automatically "dials the same tiny set of endpoints." Whoever controls those domains, he said, could take over the router and use it to access other devices connected to the same network.
Routers serve as the gateway between internet-connected devices and the wider internet, directing traffic to computers, smartphones, smart televisions, cameras, and other connected equipment. Because routers manage that traffic, a vulnerability affecting them can expose an entire home or business network.
Baines estimates that at least 100,000 of these routers are deployed worldwide. He said most people who bought one for a small business or home office would likely have no clue it could allow this sort of access.
"If I have it in my lab, in my lab at my university, you just invited them straight into your lab and they can roam the network as they choose," Baines said. "The capabilities are devastating."
What's proven, what's alleged
What's established here is narrow but real: VulnCheck found a specific technical mechanism in specific router models that phones home to a fixed set of domains, and a party controlling those domains could plausibly use that access to reach other devices on the network. That's a documented vulnerability, reported by the researcher who found it.
Western governments have warned for years about hackers exploiting small office and home office routers and other internet devices to gain access to networks for later intrusions and cyberespionage. Beijing regularly denies condoning or carrying out cyberattacks or cyberespionage. VulnCheck's disclosure does not establish who, if anyone, controls the endpoints the affected routers contact, or whether the backdoor was built deliberately or is the product of sloppy engineering. That distinction matters: a hidden pathway into a network is dangerous regardless of motive, but "backdoor exists" and "backdoor was built for espionage" are different claims, and only the first is backed by the research so far.
The bigger pattern
The finding adds to broader scrutiny of Chinese-made networking equipment. In March, the Federal Communications Commission announced restrictions on imports of certain foreign-made consumer routers over national security concerns, saying such devices had been exploited by malicious actors to target U.S. households, disrupt networks, conduct espionage, and steal intellectual property. The FCC also said foreign-made routers were involved in the Volt, Flax, and Salt Typhoon cyberattacks targeting U.S. infrastructure.
Separately, Texas filed a lawsuit in February against TP-Link Systems, alleging the networking company exposed American consumers' devices to Chinese regime access. TP-Link Systems, which was spun off from a Chinese company, said in response that it would "vigorously defend" its reputation, called the allegations "without merit," and said the Chinese communist regime has no form of ownership or control over the company, its products, or user data.
Those cases involve a different manufacturer than the one VulnCheck examined, but they reflect the same underlying concern driving regulatory action this year. A single vulnerability in one manufacturer's products, however serious, isn't proof of a coordinated state effort — but the scale here isn't trivial either. An estimated 100,000 deployed devices sold under two consumer-facing brand names, with owners who have no way of knowing their router is reaching out to a fixed set of remote domains, is a concrete, present-tense risk regardless of who is behind it.
What happens next
VulnCheck published a list of the 20 affected models and urged organizations to check whether any remain deployed on their networks, identifying devices by model number rather than brand name since Zbtlink manufactures routers for other companies under OEM and ODM agreements. The company recommended replacing affected devices where possible, restricting remote management access, and installing firmware updates if security fixes become available.
Shenzhen Zhibotong Electronics/Zbtlink did not respond to a request for comment reported in the original disclosure. Whether the manufacturer issues a fix, and whether regulators take further action against these specific brands, remains an open question.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.