In recent years, Western lawmakers have repeatedly pushed back against Chinese apps and devices, citing national security concerns. However, while attempts to ban TikTok have failed, major hardware makers like Huawei and ZTE remain unable to sell their communications equipment in the United States. A new report from threat intelligence firm VulnCheck appears to confirm what authorities have been saying for some time: Purchasing electronic devices made in China could pose a risk to your privacy.
VulnCheck discovered a backdoor (dubbed EndlessDoors) in at least 20 different types of router firmware, all created by a Chinese company called Zbtlink (which also goes by the name Wiflyer). Simply plug in a router using the affected firmware and it will automatically attempt to reach a remote server in China every 35 seconds. If successful, it opens a root terminal which allows the server owner to take full control of the router itself. Worse still, because it is traffic going directly from the router, it can pass through traditional firewalls.
Zbtlink representatives claim that this feature was designed to facilitate after-sales support and that they immediately suspended the sale of the affected routers. Unfortunately, Zbtlink also “white labels” its products, selling them to third-party companies and only modifying the branding. Further research by VulnCheck revealed that an American company called Deep Orange sold a rebranded Zbtlink router, although the unit tested predated EndlessDoors. Ultimately, it’s virtually impossible to know the true extent of the problem without accessing Zbtlink’s customer records.
How to know if your router is vulnerable
Even though Zbtlink no longer lets you download router firmware containing a backdoor, an unknown number of routers still have it installed. VulnCheck found that the model number sometimes stays the same even after changing brands, but not always. If you think you have purchased a compromised router, checking the model number should be your first step.
It is possible for users to prevent the backdoor from working. You could, for example, block all traffic to the remote server or install different router firmware, thereby removing the backdoor completely. The problem is that these approaches require time, an understanding of the network, and a level of comfort in tweaking router settings that most everyday consumers don’t have. The simplest solution is to simply replace your router with a router from a reputable brand such as Cisco, Belkin or Netgear.
Now, just because a Chinese company included a backdoor in its hardware doesn’t mean all Chinese routers are dangerous. That said, it’s a reminder that generic electronics aren’t always as good a deal as they initially seem. In addition to all the cool things your router can do, at a basic level it controls every web page you see and how every device on your local network accesses the Internet. With this in mind, can you really afford to take this risk?
