VulnCheck found a backdoor in Zbtlink routers. Chinese router maker Zbtlink then replied the code in its firmware is "solely intended for after-sales maintenance."
Its download page has since pulled the affected firmware over "firmware security vulnerabilities." ๐
VulnCheck's Jacob Baines says 20+ Zbtlink models ship with a root-level implant that phones home to a hardcoded C2 with no authentication, anyone on the network path can hijack it.
Stay vigilant. These routers are sold as ZBT, ZBTWiFi and Wiflyer on Amazon and Alibaba.