Chinese WiFi Router Backdoor Scandal: What Shoppers Need to Know About Security Threats
Researchers expose hidden security threats in budget routers sold on Amazon and other US retailers.
Cybersecurity researchers have uncovered a serious security crisis affecting numerous WiFi routers sold to US consumers. A Chinese manufacturer called Zbtlink has been linked to multiple hidden backdoors embedded in router firmware, raising alarm about potential unauthorized remote access and data theft. The discovery reveals that these devices may have been compromised for years, with no immediate fixes available.
Multiple Backdoors Discovered in Popular Router Models
Researchers from VulnCheck, a cybersecurity firm, identified three separate backdoors in Zbtlink routers. The first backdoor, called Endlessdoors, was uncovered earlier this month. Subsequent investigation revealed two additional hidden entry points: SpeakingStone and DarkLantern. These backdoors are particularly concerning because they allow attackers to execute commands on the devices from anywhere on the internet with no authentication required.
The discovery began when researchers purchased an 88 dollar WiFi router on Amazon from a vendor called Deep Orange Technology. The device turned out to be a repackaged Zbtlink model from 2014, but its firmware dated back to 2019 and contained two of the three identified backdoors. This raises questions about the age and security status of products still being sold through major retailers.
How the Backdoors Work and What Attackers Can Do

The SpeakingStone backdoor operates by secretly connecting to Zbtlink servers, bypassing standard firewall protections. It contains eight different malicious functions, including the ability to steal internet service provider login credentials and redirect website traffic to fraudulent domains through DNS hijacking. Security researchers describe it as a surveillance implant designed for data theft and espionage.
The DarkLantern backdoor works similarly but communicates differently, making it reachable directly from the internet without any protective barriers. Researchers have already found 203 instances of DarkLantern across 22 countries in 16 different router models, with 103 of those located in the United States. These findings represent only the discovered cases, and the actual number of compromised devices is likely much higher.
When researchers set up a security monitoring technique called sinkholing by taking control of a backup command server, they detected 390 unique devices attempting to communicate with Zbtlink control infrastructure. Of those, 363 were confirmed as Zbtlink products sold to major Chinese wireless carriers, suggesting the breach extends far beyond consumer devices.
Which Router Models Are Affected
Affected Zbtlink models include WE1326, WE2426-C, WE357, WE5926, WE5926-EC_QP, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WF3526-P, WG108, WG3526, L3_V2_8, ZBT-7628, and ZBT-7621. Some of these same models also contain the Endlessdoors vulnerability. Additionally, routers sold under third-party brand names, including some MoreQuick branded devices, have been compromised. The devices were marketed through US, Canadian, and Australian retailers, often without consumers knowing the actual origin or manufacturer.
Researchers warn that quality WiFi routers from reputable manufacturers without security vulnerabilities should be prioritized over budget alternatives of questionable origin.
What Zbtlink Says About the Problem

When initially confronted about the Endlessdoors backdoor, Zbtlink claimed it was merely an after-sales support tool designed to help troubleshoot customer issues upon explicit request. The company stated it would suspend sales of affected models and remove firmware from its official website. However, as of now, no patched or updated firmware has been released to fix any of the three identified backdoors.
The discovery of additional backdoors suggests the security problems go much deeper than Zbtlink’s explanation indicates. Security experts argue that a legitimate technical support tool would not operate covertly and would not include surveillance functions like credential theft or DNS hijacking.
What This Means for Buyers and Your Network Security
This situation underscores the risks of purchasing routers from unfamiliar manufacturers or heavily discounted products from unknown third-party brands. Compromised routers can intercept all data flowing through your internet connection, steal login credentials, and serve as entry points for broader network attacks. Homeowners and small business operators using these devices are potentially at risk of identity theft, financial fraud, and data breaches.
The Trump administration has already moved to restrict new foreign-manufactured routers from entering the US market due to similar espionage concerns. Although an exemption process exists through the FCC, no Chinese company has yet received approval to import routers under the new regulations. This reflects growing recognition that network hardware security is a critical national concern.
Consumers who believe they own an affected router should consider replacing it with a device from an established manufacturer with a clear security track record. When shopping for affordable router options, verify the brand name and manufacturer on the product listing and packaging. Stick with well-known brands that provide regular security updates and maintain transparent customer support channels.
Network security begins at the router level, and using compromised hardware puts your personal information and connected devices at constant risk.
