White-Label Routers Ship With Root Implant Enabled

These routers are already compromised when they leave the box. The problem is not a missing patch or a weak default password. The device comes with a hidden remote-control implant enabled by default, running as root and phoning home without login or encryption, so the normal trust signal — brand name and storefront — does not tell you whether the firmware is clean. VulnCheck found the implant, called ENDLESSDOORS, in Zbtlink white-label routers including the Z8102AX-2DSIM / AX3000 family. The same code also shows up under Wiflyer and Zbtwifi branding, and the devices were sold through Amazon, AliExpress, Alibaba, and related storefronts. The implant is a customized rctl client that reaches out to its command server and can accept shell commands as uid 0. That makes identification and containment harder than a normal product advisory. Matching one model string is not enough, because the same preloaded control path can appear across multiple retail brands and markets under different names.

Part of the PlainSec briefing for 2026-08-05

Every edition of this story: White-Label Routers Ship With Root Implant Enabled

Sources