ZBT Firmware Backdoors Cross Brand Lines

VulnCheck’s Jacob Baines found that ZBT router firmware has carried multiple manufacturer-built backdoors over several years, not just one recent implant, and that the same code ships worldwide under many white-label brands. ZBT exports to more than 50 countries, so the exposed devices are not confined to one label or one market. One of the implants phones home after boot to a domain it controls, then opens a remote-control channel with root privileges. Because the router makes the outbound connection first, the hidden command path can pass through inbound firewall rules; that can let an outsider spy on traffic, steal credentials, or use the box as a foothold into the rest of the network. For buyers and operators, the risk sits below the brand name on the chassis: a router that looks like one vendor’s product may be running ZBT firmware underneath. That means inventory and trust decisions based only on the printed brand can miss the real exposure, especially in small-office and MSP-managed fleets that mix OEM hardware.

Part of the PlainSec briefing for 2026-08-28

Editions

Sources