White-Label Routers Ship With Root Implant Enabled

These routers are already compromised when they leave the box. The problem is not a missing patch or a weak default password. The device comes with a hidden remote-control implant enabled by default, running as root and phoning home without login or encryption, so the normal trust signal — brand name and storefront — does not tell you whether the firmware is clean. VulnCheck found the implant, called ENDLESSDOORS, in Zbtlink white-label routers including the Z8102AX-2DSIM / AX3000 family. The same code also shows up under Wiflyer and Zbtwifi branding, and the devices were sold through Amazon, AliExpress, Alibaba, and related storefronts. The implant is a customized rctl client that reaches out to its command server and can accept shell commands as uid 0. That makes identification and containment harder than a normal product advisory. Matching one model string is not enough, because the same preloaded control path can appear across multiple retail brands and markets under different names.

Sources