Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
History

Wed, 05 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
Title ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
First Time appeared Zbtlink
Zbtlink cpe2801 Firmware
Zbtlink we1026-5g-wd Firmware
Zbtlink we1326 Firmware
Zbtlink we2007 Firmware
Zbtlink we2008-dsim Firmware
Zbtlink we2416 Firmware
Zbtlink we3326 Firmware
Zbtlink we5927 Firmware
Zbtlink we5931 Firmware
Zbtlink we5931ac Firmware
Zbtlink we826-t3-dsim Firmware
Zbtlink wg108 Firmware
Zbtlink wg1602 Firmware
Zbtlink wg1608-dsim Firmware
Zbtlink wg209 Firmware
Zbtlink wg2105 Firmware
Zbtlink wg2107 Firmware
Zbtlink wg259 Firmware
Zbtlink wg3526 Firmware
Zbtlink z8102ax Firmware
Weaknesses CWE-506
CPEs cpe:2.3:o:zbtlink:cpe2801_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we1026-5g-wd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we1326_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we2007_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we2008-dsim_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we2416_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we3326_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we5927_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we5931_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we5931ac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:we826-t3-dsim_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg108_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg1602_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg1608-dsim_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg209_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg2105_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg2107_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg259_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:wg3526_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zbtlink:z8102ax_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zbtlink
Zbtlink cpe2801 Firmware
Zbtlink we1026-5g-wd Firmware
Zbtlink we1326 Firmware
Zbtlink we2007 Firmware
Zbtlink we2008-dsim Firmware
Zbtlink we2416 Firmware
Zbtlink we3326 Firmware
Zbtlink we5927 Firmware
Zbtlink we5931 Firmware
Zbtlink we5931ac Firmware
Zbtlink we826-t3-dsim Firmware
Zbtlink wg108 Firmware
Zbtlink wg1602 Firmware
Zbtlink wg1608-dsim Firmware
Zbtlink wg209 Firmware
Zbtlink wg2105 Firmware
Zbtlink wg2107 Firmware
Zbtlink wg259 Firmware
Zbtlink wg3526 Firmware
Zbtlink z8102ax Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-05T14:20:12.478Z

Reserved: 2026-07-27T16:27:47.648Z

Link: CVE-2026-66747

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T12:30:12Z