CVE-2026-66747Disclosure

MEDIUM

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

5.5/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 16 mentions across 7 observed days

What's happening

  • Active exploitation reported across 5 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 14 signals
  • Disclosure: 9 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 5 mentions (2026-08-07); latest day: 1
  • 16 total mentions across 7 days

Deep dive

Activity timeline16 mentions / 7d
01345Mentions · 2026-08-05: 3Mentions · 2026-08-06: 3Mentions · 2026-08-07: 5Mentions · 2026-08-08: 1Mentions · 2026-08-10: 2Mentions · 2026-08-29: 1Mentions · 2026-09-16: 1PoC Mentioned / Linked · 2026-08-06: 1PoC Mentioned / Linked · 2026-08-07: 1Active Exploitation · 2026-08-06: 2Active Exploitation · 2026-08-07: 1Active Exploitation · 2026-08-10: 1Active Exploitation · 2026-08-29: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-10: 1Technical Details · 2026-08-05: 2Technical Details · 2026-08-06: 3Technical Details · 2026-08-07: 5Technical Details · 2026-08-08: 1Technical Details · 2026-08-10: 2Technical Details · 2026-08-29: 108-0508-0608-0708-0808-1008-2909-16
Signal classification3 categories
Disclosure
960.0%
Active Exploitation
533.3%
General
16.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-08-053
Disclosure2General1
2026-08-063
Active Exploitation2Disclosure1
2026-08-075
Active Exploitation1Disclosure4
2026-08-081
Disclosure1
2026-08-102
Active Exploitation1Disclosure1
2026-08-291
Active Exploitation1
Full discourse16 posts
  • 中国人权-Human Rights in China@hrichina
    Active Exploitation

    【Zbtlink路由器留有后门不断传输数据至中国】美国网络安全公司 VulnCheck 于 8 月 5 日公布研究报告,指深圳智博通电子(Zbtlink/ZBT)出厂的路由器固件中预装了一个后门程序。研究人员将其命名为 ENDLESSDOORS,漏洞编号 CVE-2026-66747。 这个程序伪装成 Linux 系统里随处可见的内核线程名 kworker,以 root 权限常驻运行,由厂商自己的开机脚本 skworker 拉起。设备一通电就持续向几个固定的境外指挥控制服务器主动外连,其中两个主要节点分别托管在阿里云上海与深圳。整个通信过程没有任何身份验证,也没有加密:服务器发来的内容一律以最高权限执行,一条预留口令就能开出一个交互式 root shell。由于是设备自己往外拨号,NAT 与常规防火墙并不构成阻碍,一台藏在多重内网之后的机器,与直接暴露在公网上的机器同样容易被接管。 VulnCheck 称,该公司官网下载页上约二十款机型的全部固件都带有这一组件,跨越数年的版本;而智博通同时对外提供贴牌代工,同样的硬件与固件会换上别家品牌出售,真实受影响的范围无从统计。研究团队罕见地放弃了业界通行的协调披露流程,理由很直接:这不是厂商无意留下的缺陷,而是厂商自己装进产品、并设置为开机启动的东西,没有补丁可以协调。 这类廉价的 4G/5G 移动路由常被用于随身办公、车载和临时驻点,当设备本身就是监听入口,加密通讯之外的元数据与整个内网流量都暴露在风险之中,各界需对此提高警惕。 相关分析原文👇 https://www.vulncheck.com/blog/zbt-endlessdoors

    Post summary

    The Zbtlink routers ship with a preinstalled backdoor called ENDLESSDOORS that actively connects to external C2 servers, enabling unauthenticated root shells; no patch or work‑around is available.

    5613353116.6K
    94.5K followersView on X
  • YetAgain@UnbrokenKR
    Disclosure

    로이터통신은 5일(현지시간) 사이버보안업체 벌른체크(VulnCheck)를 인용해, 중국 선전의 통신장비업체 Zbtlink가 생산한 공유기 20여 개 모델에서 원격접속이 가능한 코드가 발견됐다고 보도했다. ‘Endlessdoors’로 명명된 이 취약점(CVE-2026-66747)은 위험도 9.3점의 치명적 등급으로 평가됐다. 해당 코드는 기기 부팅과 함께 자동 실행돼 약 35초마다 특정 IP와 중국 등록 도메인에 접속하며, 공격자가 공유기 관리자 권한으로 명령을 실행하고 내부 네트워크의 PC·스마트폰까지 공격할 가능성이 있다. 특히 이 코드는 외부에서 감염된 악성코드가 아니라 제조사가 배포한 공식 펌웨어에 포함돼 있었다.

    Post summary

    Reuters reports the discovery of CVE‑2026‑66747, a critical remote code execution flaw in Zbtlink routers that auto‑executes a malicious script at boot, yet no PoC, exploit tool, or active exploitation details are provided.

    070120359
    5.0K followersView on X
  • retr0@retr0hxx

    NTTセキュリティ・ジャパンの8月レポート。VulnCheckが調べた中国メーカーZbtlink製ルーターの話をまとめている。出荷時から「ENDLESSDOORS」というバックドアが入っており、約35秒おきに外部サーバーへつながる。認証も暗号化もない通信で、送られてきたコマンドをrootで実行する。CVE-2026-66747。影響は10万台超。修正ファームウェアは出ていない。後から見つけたバグではなく、最初から製品に入っている遠隔操作だ。NTTは件数や悪用対策だけでは足りず、誰が作り誰が保守するかまで見ろ、と書いている。パッチで直せないなら、倉庫や現場のルーターはそのまま信用できない。ホテルや支店の安いCPEが外部からシェルを取れる箱になる。

    000961.5K
    830 followersView on X
  • 🌸てん_株式投資@earlyfield2023
    Disclosure

    概要 • 中国・深センのZbtlink(深圳市智博通電子)が製造するルーター約20機種のファームウェアに、外部からroot権限で操作可能な隠しバックドア「ENDLESSDOORS」(CVE-2026-66747)が組み込まれていることが判明しました。 • 調査した21のファームウェアイメージすべてに含まれ、機器の起動時に自動実行されます。 • 影響を受ける機器は世界で少なくとも10万台以上が稼働していると推定されています。 • Zbtlinkブランドだけでなく、WiflyerブランドやOEM/ODM製品としても流通しており、ロゴではなく型番で確認する必要があると注意喚起されています。 バックドアの仕組み • Linux向けの遠隔操作ツール「rctl」を改変したもの。 • ルーター側から中国のC2(指令・制御)サーバーへ接続する「外向き通信」型のため、ファイアウォールの内側でも通信が成立します。 • 約35秒ごとに特定のIPアドレスや中国登録ドメインへ自動接続を試みます。 • 認証なしで送られたコマンドをroot権限で実行可能で、対話型シェルの起動も可能です。 • プロセス名を「kworker」に偽装して目立たなくしています。 対象機種の例 CPE2801、WE1026-5G-WD、WE1326、WE2007、WE2008-DSIM、WE2416、WE3326、WE5927、WE5931、WE5931AC、WE826-T3-DSIM、WG108、WG1602、WG1608-DSIM、WG209、WG2105、WG2107、WG259、WG3526、Z8102AX-2DSIM など。 メーカーの対応 Zbtlinkは指摘を受け、該当機種の販売を一時停止し、影響のあるソフトウェアをサイトから削除。アップデートを準備中と表明しています。同社は「アフターサービス用の技術サポートツールで、顧客の明示的な依頼と承認がある場合のみ使用するもので、不正アクセスに使われたことはない」と主張しています。 推奨される対策 • 該当機種を使用している場合は、ネットワークから切り離し、交換を検討する。 • 外向き通信の厳格な制御やネットワーク分離を実施する。 • 修正ファームウェアが提供されるまで使用を控える。 この発見は、中国製ネットワーク機器に対する西側諸国の安全保障上の懸念を改めて強める内容です。米国では既に外国製コンシューマー向けルーターの新規モデル認証を制限する動きが進んでいます。 詳細はVulnCheckの公式レポートやビジネス+ITの記事で確認できます。ご自身の環境で該当機種がないか確認することをおすすめします。​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​ 中国製ルータ20機種に「隠しバックドア」、世界10万台超か…35秒ごとに外部通信判明(ビジネス+IT) #Yahooニュース https://news.yahoo.co.jp/articles/e1dcb713ff3473e94caf201d1c72e5c053852062?source=sns&dv=sp&mid=other&date=20260808&ctg=it&bt=tw_up

    Post summary

    The article discloses a hidden backdoor (“ENDLESSDOORS”) in Zbtlink router firmware that grants root access via a modified rctl tool, notes widespread deployment, and informs of pending vendor patches and user mitigation steps.

    200401.7K
    15.9K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    Zbtlink WiFi routers ship with ENDLESSDOORS malware embedded in firmware, enabling remote command execution with root privileges via preinstalled implants that connect to external C2 servers (CVE-2026-66747) without user compromise. https://cyberinsider.com/chinese-zbtlink-wifi-routers-ship-with-endlessdoors-malware/

    Post summary

    The article alleges that Zbtlink routers ship with firmware containing Endlessdoors malware that exploits CVE-2026-66747 to remotely execute root‑level commands via preinstalled implants, indicating active in‑the‑wild exploitation without user action.

    01012840
    22.6K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Factory-installed C2 backdoor ENDLESSDOORS found in Chinese 🇨🇳 Zbtlink router firmware, giving root shell access to 100,000+ deployed units worldwide with no patch available. Key findings: - CVE-2026-66747: the ENDLESSDOORS implant is baked into vendor firmware and started at boot by the manufacturer's own init script. It beacons every 35 seconds to hardcoded C2 over unencrypted, unauthenticated channels on ports 7000 and 7001. Anyone controlling the destination, or sitting on the path, gets a root shell. No inbound exposure required: devices behind firewalls are equally compromised. - Confirmed in 21 firmware images across 20+ models including CPE2801, WE/WG series, and Z8102AX-2DSIM, sold under Zbtlink and Wiflyer brands. No fixed firmware exists and VulnCheck did not pursue coordinated disclosure because the behavior appears intentional. - For ICS/OT responders, the forensic tell is two userland kworker processes plus the files /usr/sbin/kworker, /usr/lib/librctl.so, /etc/kworker.cfg, and /etc/init.d/skworker on the device. - Defanged IOCs: zbtctl.epplink[.]net, online-string[.]com, rbdg4nzqadui.wikaba[.]com, 47.100.190[.]96, 47.107.224[.]89, 45.32.81[.]152, 43.248.136[.]125. Inventory OT edge gear by model number, not brand label. Block the IOCs at egress and DNS, alert on outbound ports 7000/7001 from infrastructure segments, and replace confirmed devices. Suricata, Snort, and YARA rules are in the VulnCheck report. #DFIR_Radar

    Post summary

    A factory‑installed backdoor in Zbtlink routers (CVE-2026-66747) provides root shell access on over 100,000 units, with no patch available and active exploitation confirmed.

    10120205
    1.8K followersView on X
  • 網駭實驗室@lfcba8178
    Disclosure

    💀 你買的路由器,出廠就是別人的肉雞。 不是被駭。是「原廠設計」。 中國 Zbtlink 至少 20 款路由器,韌體內建後門 ENDLESSDOORS(CVE-2026-66747): ☠️ 開機就自動連回遠端伺服器,每 35 秒敲一次門 ☠️ root 權限,對方叫它做什麼它就做什麼 ☠️ 連對方是誰都不驗證——任何人劫持連線就是新主人 ☠️ 偽裝成正常系統程序,你根本看不出來 ☠️ 官網 21 個韌體檔,21 個全有後門,塞了超過 2 年 你以為躲在防火牆後面就安全?連線是路由器「自己爬出去」的,防火牆形同虛設。 最狠的是:ZBT 是代工廠。你手上那台便宜的白牌 4G 路由器、雜牌 CPE,拆開來可能就是它。20 款只是冰山一角。 原廠回應:「這是售後維護功能啦」 一個不驗證身分、root 執行任意指令、還會隱藏自己的維護功能。嗯。 現在就去清查你家、你公司機房裡的白牌路由器。 ref:https://www.ithome.com.tw/news/177962 @PTTNetSecurity @cheng527 @Military_idv_tw

    Post summary

    The post discloses a backdoor in certain router firmware (CVE‑2026‑66747) that runs with root privileges and automatically communicates with a remote server, but it does not provide a PoC, exploit, or patch information.

    20010164
    76 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-66747: a Zbtlink router backdoor named ENDLESSDOORS gives unauthenticated remote code execution as root. No fix exists. CVSS 9.8. #Zbtlink #RouterBackdoor #CVE #IoT #CyberSecurity http://securityonline.info/zbtlink-router-backdoor/

    Post summary

    A newly disclosed CVE-2026-66747 exposes a Zbtlink router backdoor that allows unauthenticated root-level remote code execution, rated CVSS 9.8, with no patch available.

    00021461
    12.9K followersView on X
  • Caitlin Condon@catc0n
    General

    We've assigned CVE-2026-66747 to track backdoored firmware versions. Our blog also has guidance for defenders, including affected firmware images, hashes, network indicators, a YARA rule, and network signatures (Suricata / Snort): https://www.vulncheck.com/blog/zbt-endlessdoors

    Post summary

    The blog supplies defenders with detection rules and indicators for CVE-2026-66747 but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    01020493
    3.6K followersView on X
  • Naoshima⚓️Shodoshima (直島⚓️小豆島)@miiraku2023
    Disclosure

    @nikkei In Aug. 2026, VulnCheck disclosed a critical supply-chain security flaw (tracked as CVE-2026-66747 with a CVSS score of 9.3) dubbed "ENDLESSDOORS" affecting over 20 models of Wi-Fi routers manufactured by Chinese firm Zbtlink and sold globally under budget brands like Wiflyer.

    Post summary

    The tweet announces the discovery of a critical supply‑chain vulnerability (CVE‑2026‑66747) with a CVSS score of 9.3 affecting over twenty Wi‑Fi router models from Zbtlink.

    11000243
    110 followersView on X
  • Nineshoot@nineshoot
    Active Exploitation

    VulnCheck registered the one unclaimed backup domain and stood up their own listener. Within days: hundreds of check-ins, 99.5% from inside China. CVE-2026-66747, CVSS 9.3. https://t.co/5kM0uLeAg4

    Post summary

    CVE-2026-66747 is reportedly actively exploited, evidenced by numerous check‑ins from China, with no PoC, patch, or exploit code details shared.

    1000071
    71 followersView on X
  • Naoshima⚓️Shodoshima (直島⚓️小豆島)@miiraku2023
    Disclosure

    @nikkei In Aug. 2026, VulnCheck disclosed a critical supply-chain security flaw (tracked as CVE-2026-66747 with a CVSS score of 9.3) dubbed "ENDLESSDOORS" affecting over 20 models of Wi-Fi routers manufactured by Chinese firm Zbtlink and sold globally under budget brands like Wiflyer.

    Post summary

    VulnCheck has announced CVE-2026-66747, a high‑severity supply‑chain flaw affecting multiple Zbtlink Wi‑Fi router models.

    10000201
    110 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #LowCompleteness ENDLESSDOORS Is Phoning Home. Pick Up. | 05-08-2026 Source: https://www.vulncheck.com/blog/zbt-endlessdoors Key details below ↓ 💀Threats: Endlessdoors, 🎯Victims: Hospitality, Transportation, Network infrastructure 🔓CVEs: CVE-2026-66747 \[[Vulners](https://vulners.com/cve/CVE-2026-66747)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown 📚TTPs: ⚔️Tactics: 1 🛠️Technics: 0 🤖LLM extracted TTPs:` T1036.005, T1037.004, T1059.004, T1095, T1105, T1568, T1571, T1573 🧨IOCs: - Domain: 3 - IP: 4 - Hash: 26 - File: 1 💽Software: BusyBox, Alibaba Cloud 🔢Algorithms: sha256 🔠Functions: popen 💻Platforms: mips YARA: Found #threatreport: The ENDLESSDOORS malware exemplifies a sophisticated and covert attack technique, allowing threat actors to gain unauthorized access to affected devices by leveraging outbound communication. It utilizes a client-server model where the implant, residing in compromised devices, contacts a command-and-control (C2) server. The specific commands for the implant include requests to run operations as root and establish a root shell, revealing a clear intent to exploit system vulnerabilities. This malware is notable for its ability to bypass traditional network defenses by initiating connections from within the victim's network, evading measures like NAT or standard firewall rules. This capability means that even devices behind multiple layers of security can be compromised as long as they can reach the C2 server, exemplified by a case where the C2 server was found on a DDNS service. The primary identifier for this vulnerability has been cataloged as CVE-2026-66747. Multiple router models have been discovered to be affected, with one notable instance being the AX3000, which communicates with the http://wikaba.com endpoint. Other models connect to the domain http://zbtctl.epplink.net, which resolves to an Alibaba Cloud IP address, underscoring the use of cloud services for hosting malicious infrastructure. Organizations are urged to conduct thorough inventories of their devices, focusing on specific models associated with the ENDLESSDOORS malware, such as Zbtlink routers. Detection and response measures for the ENDLESSDOORS implant include searching for signs of its presence, such as unusual processes in the operating system and the presence of specific configuration files. Network actions associated with the implant are also critical, specifically monitoring egress traffic on ports 7000 and 7001, which are utilized for communication with the C2 infrastructure. To mitigate risks, it is recommended to block and monitor traffic to known malicious endpoints, implement alerts based on outbound traffic behaviors, and consider device replacement in instances where compromised hardware cannot be secured reliably. Further detection capabilities can be enhanced through the application of established network security rules, specifically tailored for Suricata and Snort intrusion detection systems, as well as the development of a YARA rule for identification of ENDLESSDOORS implants based on specific binary signatures and operational characteristics. This comprehensive approach allows organizations to respond effectively to this emerging threat, minimizing the risk of successful exploitation.

    Post summary

    This report details an actively exploited vulnerability (CVE‑2026‑66747) causing malicious implants in routers, providing mitigation guidance but no patch or PoC, confirming ongoing real‑world attacks.

    00000178
    758 followersView on X
  • Xploitzone@Xploitzone_01
    Disclosure

    🚨 Hidden Router Backdoor Researchers uncovered ENDLESSDOORS, a built-in root implant affecting 20+ Zbtlink router models. It silently phones home every 35 seconds, enabling remote command execution and full device takeover. 🔗 https://xploitzone.com/zbtlink-endlessdoors-cve-2026-66747/ #RouterSecurity #Malware https://t.co/sGpGuApaBk

    Post summary

    Researchers identified a new root implant (ENDLESSDOORS) in Zbtlink routers that allows remote command execution and device takeover, as documented in CVE-2026-66747.

    00000103
    11 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-66747 - Critical RCE via hidden ENDLESSDOORS implant in Zbtlink routers. Backdoor runs as root, phones home over cleartext. CVSS 9.8. Unpatched. Isolate devices now. #CVE #infosec #IoT https://www.valtersit.com/cve/CVE-2026-66747/ #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu

    Post summary

    This tweet announces a critical RCE vulnerability (CVE‑2026‑66747) in Zbtlink routers due to a hidden ENDLESSDOORS implant, noting it is unpatched and urging device isolation.

    00000153
    1.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-66747 Unauthenticated Remote Code Execution via Embedded Implant in Zbtlink Router Firmware https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-66747

    Post summary

    The snippet announces CVE‑2026‑66747 as an unauthenticated RCE in Zbtlink router firmware, with no additional technical, exploit, or mitigation details provided.

    0000094
    4.1K followersView on X

Explore more