ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant

Summary

CVECVE-2026-66747
StatePUBLISHED
AssignerVulnCheck
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-05 11:16:25 UTC
Updated2026-08-05 11:16:25 UTC
DescriptionZbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.

Risk And Classification

Primary CVSS: v4.0 9.3 CRITICAL from [email protected]

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Problem Types: CWE-506 | CWE-506 CWE-506 Embedded Malicious Code


VersionSourceTypeScoreSeverityVector
4.0[email protected]Secondary9.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C...
4.0CNACVSS9.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
3.1[email protected]Primary9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
3.1CNACVSS9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0 Breakdown

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Sub Conf.
None
Sub Integrity
None
Sub Availability
None

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CVSS v3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Zbtlink CPE2801 Firmware affected 22.10.09 custom MIPS, ARM
CNA Zbtlink WE1026-5G-WD Firmware affected 21.04.07 custom MIPS, ARM
CNA Zbtlink WE1326 Firmware affected 22.02.18_1 custom MIPS, ARM
CNA Zbtlink WE2007 Firmware affected 23.08.12 custom MIPS, ARM
CNA Zbtlink WE2008-DSIM Firmware affected 23.08.11 custom MIPS, ARM
CNA Zbtlink WE2416 Firmware affected 21.03.22_1 custom MIPS, ARM
CNA Zbtlink WE3326 Firmware affected 20.09.30 custom MIPS, ARM
CNA Zbtlink WE5927 Firmware affected 22.08.10 custom MIPS, ARM
CNA Zbtlink WE5931 Firmware affected 22.05.31 custom MIPS, ARM
CNA Zbtlink WE5931AC Firmware affected 22.05.31 custom MIPS, ARM
CNA Zbtlink WE826-T3-DSIM Firmware affected 21.12.21 custom MIPS, ARM
CNA Zbtlink WG108 Firmware affected 21.08.06_1 custom MIPS, ARM
CNA Zbtlink WG209 Firmware affected 21.07.28 custom MIPS, ARM
CNA Zbtlink WG259 Firmware affected 21.03.23 custom MIPS, ARM
CNA Zbtlink WG1602 Firmware affected 23.10.11 custom MIPS, ARM
CNA Zbtlink WG1608-DSIM Firmware affected 23.03.16 custom MIPS, ARM
CNA Zbtlink WG2105 Firmware affected 22.05.30 custom MIPS, ARM
CNA Zbtlink WG2107 Firmware affected 22.09.08 custom MIPS, ARM
CNA Zbtlink WG3526 Firmware affected 22.11.01 custom MIPS, ARM
CNA Zbtlink ZBT-Z8102AX-2SIM Firmware affected 7.6.7.2-25.0814_114432 custom ARM

References

ReferenceSourceLinkTags
www.zbtlink.com/pages/zbt-router-firmware-download [email protected] www.zbtlink.com
www.vulncheck.com/advisories/zbt-endlessdoors [email protected] www.vulncheck.com
www.vulncheck.com/blog/zbt-endlessdoors [email protected] www.vulncheck.com
github.com/ycsunjane/rctl [email protected] github.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

CNA: Jacob Baines of VulnCheck (en)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report